review-prompt
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
review_prompt.pyexecutes commands defined in the--validatorand--smokeCLI flags usingsubprocess.run(shell=True)in the_run_configured_commandsfunction. This is a core feature for verifying prompt performance but allows for arbitrary command execution based on CLI input. - [CREDENTIALS_UNSAFE]: The variable
SCILLM_KEYinreview_prompt.pyhas a hardcoded default value ofsk-dev-proxy-123. While likely a dummy value for development, hardcoding credentials remains a security risk. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes untrusted template and source data, allows an LLM to modify that data, and subsequently executes commands. 1. Ingestion points: Untrusted data enters the context through the
--template,--source, and--payloadflags inreview_prompt.py. 2. Boundary markers: The script uses triple backticks to delimit content in model requests, providing basic isolation. 3. Capability inventory: The skill performs file writes to the template path and executes shell commands via the_run_configured_commandsfunction. 4. Sanitization: The script strips markdown formatting fences from LLM fixes before writing them to disk, but does not further validate the content.
Audit Metadata