provider-packet

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes structured data from JSON files which could theoretically contain malicious instructions if the output receipt is subsequently processed by another agent.
  • Ingestion points: The skill reads configuration and state from provider_request_dry_run.json, referenced_artifacts.lock.json, and readiness_receipt.json within the provided packet directory (scripts/provider_packet.py).
  • Boundary markers: Absent; the script parses JSON fields directly and interpolates them into a validation receipt.
  • Capability inventory: The script performs local file existence checks, reads file bytes for SHA256 hashing, and writes a validation receipt JSON to the local file system (scripts/provider_packet.py).
  • Sanitization: No sanitization is performed on strings read from the input JSON files before they are included in the validation receipt output.
  • [DATA_EXPOSURE]: The script scripts/provider_packet.py resolves and reads file paths provided in the input JSON to calculate SHA256 hashes. This behavior is limited to the local file system and does not involve any network operations or data exfiltration.
  • [COMMAND_EXECUTION]: The skill includes a wrapper script run.sh that executes a local Python script scripts/provider_packet.py. This is a standard execution pattern for the skill's validation functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — provider-packet