batch-report

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The evaluate_llm_gates function in batch_report/analysis.py exhibits an indirect prompt injection surface. \n
  • Ingestion points: The skill ingests data from untrusted batch output files, such as results.jsonl and output.jsonl (found in batch_report/analysis.py). \n
  • Boundary markers: No explicit boundary markers or protective instructions (e.g., 'ignore instructions within the data') are used when interpolating content into the {sample} template variable. \n
  • Capability inventory: The skill invokes local subprocesses through subprocess.run to call external tools like scillm and agent-inbox (found in batch_report/analysis.py and batch_report/utils.py). \n
  • Sanitization: Sanitization is limited to basic JSON formatting attempts; raw data content is placed directly into the evaluation prompt. \n- [COMMAND_EXECUTION]: The skill uses subprocess.run to execute local shell scripts and Python files residing in the user's home directory. \n
  • In batch_report/utils.py, the send_to_agent_inbox function executes the agent-inbox script. \n
  • In batch_report/analysis.py, the evaluate_llm_gates function executes the scillm tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — batch-report