lie-detector

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The classifier.py module uses pickle.load() to deserialize a local model file. This is an unsafe practice as it allows for arbitrary code execution if the file is tampered with.
  • [PERSISTENCE_MECHANISMS]: The skill provides an install-hook command that modifies the .git/hooks directory to install a pre-commit hook. This constitutes a persistence mechanism that executes code during git operations.
  • [COMMAND_EXECUTION]: The skill frequently executes external processes and other skills via subprocess.run, including /memory, /assistant, and system utilities like git and memory-agent. This increases the overall attack surface.
  • [PROMPT_INJECTION]: The skill ingests untrusted conversation logs for analysis by machine learning models and LLMs. There is a lack of boundary markers or sanitization in scripts like llm_auditor.py, making it vulnerable to indirect prompt injection. Ingestion points: detect and report commands in lie_detector.py. Boundary markers: Absent. Capability inventory: Numerous subprocess.run calls across the logic. Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — lie-detector