compliance-timeline
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script constructs database query filters by directly interpolating user-provided inputs without sanitization.
- Evidence: In
run.sh, thecmd_difffunction interpolates${FROM_DATE}and${TO_DATE}into a filter string:local filter="doc.ts >= \"${FROM_DATE}T00:00:00Z\" AND doc.ts <= \"${TO_DATE}T23:59:59Z\"". - Risk: This allows for query injection (e.g., AQL injection) if the user provides crafted date strings containing quotes or logical operators, potentially exposing data outside the intended scope.
- [PROMPT_INJECTION]: The skill ingests and processes data from an external source (the ArangoDB memory tool), creating a surface for indirect prompt injection.
- Ingestion points:
run.shreads JSON data from../memory/run.shvia thequery_memoryfunction. - Boundary markers: Absent. The skill does not use delimiters or instructions to ignore embedded commands in the retrieved data.
- Capability inventory: The skill can execute bash commands and perform database queries via the memory service.
- Sanitization: Absent. The raw output from the database is processed and printed directly to the timeline output.
- Risk: If the database contains malicious records created by an attacker, the agent might follow instructions embedded in those records when generating the timeline summary.
- [COMMAND_EXECUTION]: The skill uses
uv runto execute inline Python scripts containing logic for data formatting. - Evidence: The
emit_dry_runandquery_memoryfunctions inrun.shuse heredocs (PYEOF) to pass Python code to theuvrunner. - Risk: While the template is static, the script passes raw database output as a command-line argument to the Python process (
$raw), which could lead to shell errors if the data volume is extremely large.
Audit Metadata