prompt-lab

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES]: The script cwe_evaluation.py performs runtime installation of Python packages (typer, rich) using pip if they are not detected in the environment. This pattern introduces a risk of executing unverified code from external registries at runtime.
  • [DYNAMIC_EXECUTION]: The pl_optimize.py and optimization.py modules implement a feedback loop where an LLM (meta-model) generates improved versions of system prompts. These generated instructions are written directly to the prompts/ directory (out_file.write_text(best_variant['prompt'])) and are used as instructions for subsequent agent actions. This allows the model to dynamically redefine its own operational logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection:
  • Ingestion points: sparta_connector.py reads data from a DuckDB database (controls, url_knowledge tables), and pl_eval_f36.py ingest engineering documents.
  • Boundary markers: Prompt templates in the prompts/ directory use [SYSTEM] and [USER] delimiters to separate instructions from data.
  • Capability inventory: The skill possesses Bash and Write permissions, executing subprocess.run in cwe_evaluation.py, pricing_core.py, and pl_find_minimum.py, and modifying its own configuration files.
  • Sanitization: There is no evidence of explicit sanitization or filtering of external content fetched from the database before it is interpolated into prompts.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to call external tools such as pip for installation and the dogpile skill for research. While these support the primary function, they provide a mechanism for arbitrary command execution if the input parameters (like the dogpile search query) are influenced by malicious data.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — prompt-lab