batch-report
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The
evaluate_llm_gatesfunction inbatch_report/analysis.pyexhibits an indirect prompt injection surface. \n - Ingestion points: The skill ingests data from untrusted batch output files, such as
results.jsonlandoutput.jsonl(found inbatch_report/analysis.py). \n - Boundary markers: No explicit boundary markers or protective instructions (e.g., 'ignore instructions within the data') are used when interpolating content into the
{sample}template variable. \n - Capability inventory: The skill invokes local subprocesses through
subprocess.runto call external tools likescillmandagent-inbox(found inbatch_report/analysis.pyandbatch_report/utils.py). \n - Sanitization: Sanitization is limited to basic JSON formatting attempts; raw data content is placed directly into the evaluation prompt. \n- [COMMAND_EXECUTION]: The skill uses
subprocess.runto execute local shell scripts and Python files residing in the user's home directory. \n - In
batch_report/utils.py, thesend_to_agent_inboxfunction executes theagent-inboxscript. \n - In
batch_report/analysis.py, theevaluate_llm_gatesfunction executes thescillmtool.
Audit Metadata