ingest-sparta

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Hardcoded API key sk-dev-proxy-123 detected in classifier.py, eval_html_extraction.py, and evidence_gate.py. This key is used for communication with a local proxy service (localhost:4001). While likely a dummy value for development, hardcoding credentials is not recommended.
  • [COMMAND_EXECUTION]: The skill makes extensive use of subprocess.run to manage the SPARTA pipeline, including running Python modules, executing shell scripts, and launching an Explorer UX. This is part of the skill's primary purpose as a thin wrapper around a complex pipeline.
  • Evidence in ingest_sparta.py: subprocess.run(cmd, cwd=str(SPARTA_ROOT), ...) to execute pipeline steps.
  • Evidence in ingest_cwe_nist.py: subprocess.run(["wget", ...]) to fetch mapping files.
  • [REMOTE_CODE_EXECUTION]: classifier.py uses joblib.load to deserialize a machine learning model from a local file path (~/.pi/models/classifiers/url_content_quality_classifier.joblib). Using joblib to load data can lead to arbitrary code execution if the source file is compromised.
  • [EXTERNAL_DOWNLOADS]: ingest_cwe_nist.py downloads a mapping CSV from MITRE's official GitHub repository. MITRE is a well-known and trusted source in the cybersecurity community.
  • [PROMPT_INJECTION]: evidence_gate.py presents an attack surface for indirect prompt injection by processing user-supplied questions through an evaluation chain and an LLM correction loop.
  • Ingestion points: validate_qra and validate_batch endpoints in evidence_gate.py accept arbitrary question strings.
  • Boundary markers: No explicit delimiters or instructions were found to separate user input from internal prompts.
  • Capability inventory: The skill can execute subprocesses and perform network requests to local services.
  • Sanitization: No input validation or escaping of the question field was identified before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — ingest-sparta