lie-detector
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
classifier.pymodule usespickle.load()to deserialize a local model file. This is an unsafe practice as it allows for arbitrary code execution if the file is tampered with. - [PERSISTENCE_MECHANISMS]: The skill provides an
install-hookcommand that modifies the.git/hooksdirectory to install a pre-commit hook. This constitutes a persistence mechanism that executes code during git operations. - [COMMAND_EXECUTION]: The skill frequently executes external processes and other skills via
subprocess.run, including/memory,/assistant, and system utilities likegitandmemory-agent. This increases the overall attack surface. - [PROMPT_INJECTION]: The skill ingests untrusted conversation logs for analysis by machine learning models and LLMs. There is a lack of boundary markers or sanitization in scripts like
llm_auditor.py, making it vulnerable to indirect prompt injection. Ingestion points:detectandreportcommands inlie_detector.py. Boundary markers: Absent. Capability inventory: Numeroussubprocess.runcalls across the logic. Sanitization: Absent.
Audit Metadata