data-audit
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
audit.pyscript is vulnerable to SQL injection through theframeworkparameter in thegapscommand. Evidence: The variable is directly interpolated into the SQL string:query += f\" AND c.control_type = '{framework}'\". This allows an attacker to execute arbitrary SQL commands, potentially leading to unauthorized data access. - [REMOTE_CODE_EXECUTION]: The script uses dynamic path manipulation to load shared modules. Evidence:
_sys.path.insert(0, str(_Path.home() / \".pi\" / \"skills\"))is used to importTaskClient. Risk: Loading code from computed paths in the home directory is risky as it depends on the security of that specific directory. - [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface. 1. Ingestion points: Data is read from
sparta.duckdb. 2. Boundary markers: None present to delimit untrusted data in the output. 3. Capability inventory: Accesses local database files and composes with thecreate-figureskill. 4. Sanitization: No evidence of escaping or filtering database content before display.
Audit Metadata