provider-packet
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes structured data from JSON files which could theoretically contain malicious instructions if the output receipt is subsequently processed by another agent.
- Ingestion points: The skill reads configuration and state from
provider_request_dry_run.json,referenced_artifacts.lock.json, andreadiness_receipt.jsonwithin the provided packet directory (scripts/provider_packet.py). - Boundary markers: Absent; the script parses JSON fields directly and interpolates them into a validation receipt.
- Capability inventory: The script performs local file existence checks, reads file bytes for SHA256 hashing, and writes a validation receipt JSON to the local file system (scripts/provider_packet.py).
- Sanitization: No sanitization is performed on strings read from the input JSON files before they are included in the validation receipt output.
- [DATA_EXPOSURE]: The script
scripts/provider_packet.pyresolves and reads file paths provided in the input JSON to calculate SHA256 hashes. This behavior is limited to the local file system and does not involve any network operations or data exfiltration. - [COMMAND_EXECUTION]: The skill includes a wrapper script
run.shthat executes a local Python scriptscripts/provider_packet.py. This is a standard execution pattern for the skill's validation functionality.
Audit Metadata