assistant

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection in the _scillm_escalate function within gateway.py and the prompt generation logic in prime_shadow.py. User-provided text is directly interpolated into prompts sent to LLM tiers.
  • Ingestion points: The validate() and classify() functions in gateway.py take arbitrary input data and strings that are processed through the inference tiers.
  • Boundary markers: Minimal markers (e.g., "Input:") are used to separate user data from system instructions, which may allow adversarial input to override the intended task logic.
  • Capability inventory: The skill possesses the capability to execute shell commands (via sibling skill interaction) and retrieve context from persona memory, increasing the potential impact of a successful injection.
  • Sanitization: No explicit escaping, filtering, or validation of user input was observed before it is embedded into the LLM prompts.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run across several files (gateway.py, prime_shadow.py, harvest.py) to orchestrate functionality by calling sibling skills like scillm, memory, and create-gpt. While these calls use argument lists rather than shell strings (mitigating standard shell injection), the pattern creates a dependency on the external scripts and allows the skill to execute significant system operations based on runtime data.
  • [REMOTE_CODE_EXECUTION]: In models.py, the skill employs joblib.load() to load scikit-learn models from paths defined in model_registry.json. joblib utilizes the pickle protocol, which is susceptible to arbitrary code execution during deserialization. If a model file or the registry configuration were compromised, loading the model would lead to execution of arbitrary Python code. This is a common practice in ML workflows but represents a significant security surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — assistant