quality-audit
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
run.shscript suggests a command to download and install theuvpackage manager fromhttps://astral.sh/uv/install.sh. This is the official distribution domain for a well-known developer tool. - [PROMPT_INJECTION]: The
quality_audit.pyscript generates prompts for 'UltraThink mode' by interpolating untrusted data from input files, creating a surface for indirect prompt injection. - Ingestion points: Data is ingested from user-specified JSON or JSONL files via the
load_inputfunction inquality_audit.py. - Boundary markers: The generated prompt uses Markdown headers and code blocks to separate fields but does not include explicit instructions to the LLM to ignore nested commands within the data.
- Capability inventory: The skill leverages the
Bash,Read, andWritetools to perform operations and generate reports. - Sanitization: There is no evidence of sanitization or escaping of input fields before they are embedded into the prompt template.
- [COMMAND_EXECUTION]: The
memory_integration.pyfile dynamically loads a taxonomy module usingimportlib.util.spec_from_file_location, andquality_audit.pymodifies the Python search path to import internal utilities from the.pi/skillsdirectory.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata