assistant
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits vulnerability to indirect prompt injection in the
_scillm_escalatefunction withingateway.pyand the prompt generation logic inprime_shadow.py. User-provided text is directly interpolated into prompts sent to LLM tiers. - Ingestion points: The
validate()andclassify()functions ingateway.pytake arbitrary input data and strings that are processed through the inference tiers. - Boundary markers: Minimal markers (e.g., "Input:") are used to separate user data from system instructions, which may allow adversarial input to override the intended task logic.
- Capability inventory: The skill possesses the capability to execute shell commands (via sibling skill interaction) and retrieve context from persona memory, increasing the potential impact of a successful injection.
- Sanitization: No explicit escaping, filtering, or validation of user input was observed before it is embedded into the LLM prompts.
- [COMMAND_EXECUTION]: The skill uses
subprocess.runacross several files (gateway.py,prime_shadow.py,harvest.py) to orchestrate functionality by calling sibling skills likescillm,memory, andcreate-gpt. While these calls use argument lists rather than shell strings (mitigating standard shell injection), the pattern creates a dependency on the external scripts and allows the skill to execute significant system operations based on runtime data. - [REMOTE_CODE_EXECUTION]: In
models.py, the skill employsjoblib.load()to load scikit-learn models from paths defined inmodel_registry.json.joblibutilizes thepickleprotocol, which is susceptible to arbitrary code execution during deserialization. If a model file or the registry configuration were compromised, loading the model would lead to execution of arbitrary Python code. This is a common practice in ML workflows but represents a significant security surface.
Audit Metadata