prompt-lab
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES]: The script
cwe_evaluation.pyperforms runtime installation of Python packages (typer,rich) usingpipif they are not detected in the environment. This pattern introduces a risk of executing unverified code from external registries at runtime. - [DYNAMIC_EXECUTION]: The
pl_optimize.pyandoptimization.pymodules implement a feedback loop where an LLM (meta-model) generates improved versions of system prompts. These generated instructions are written directly to theprompts/directory (out_file.write_text(best_variant['prompt'])) and are used as instructions for subsequent agent actions. This allows the model to dynamically redefine its own operational logic. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection:
- Ingestion points:
sparta_connector.pyreads data from a DuckDB database (controls,url_knowledgetables), andpl_eval_f36.pyingest engineering documents. - Boundary markers: Prompt templates in the
prompts/directory use[SYSTEM]and[USER]delimiters to separate instructions from data. - Capability inventory: The skill possesses
BashandWritepermissions, executingsubprocess.runincwe_evaluation.py,pricing_core.py, andpl_find_minimum.py, and modifying its own configuration files. - Sanitization: There is no evidence of explicit sanitization or filtering of external content fetched from the database before it is interpolated into prompts.
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto call external tools such aspipfor installation and thedogpileskill for research. While these support the primary function, they provide a mechanism for arbitrary command execution if the input parameters (like thedogpilesearch query) are influenced by malicious data.
Audit Metadata