review-question

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses carefully structured system prompts to define persona behavior and expert boundaries. It includes explicit negative constraints to prevent the model from mentioning or leaking internal identifiers, query languages, or database structures. Evaluation logs confirm that the system successfully resists and redirects off-topic or probing queries back to its intended domain.- [COMMAND_EXECUTION]: Benign command execution is used to interact with sibling skills such as /memory and /scillm. The implementation uses subprocess.run with list-based arguments, which is a safe practice that prevents shell injection. Additionally, the evidence_case.py module implements a strict character allowlist via _sanitize_entity_id to prevent AQL injection when interpolating user-provided entity IDs into database filter expressions.- [DATA_EXFILTRATION]: There is no evidence of unauthorized data transmission. The skill communicates with well-known LLM provider DeepSeek as a fallback mechanism for generation, which is treated as a well-known service. Sensitive data retrieval is restricted to local subprocess calls to the /memory skill, ensuring that internal data lake content remains within the local environment.- [SAFE]: The skill demonstrates a high level of security maturity, including self-auditing walkthroughs in the results directory and the removal of fragile regex-based parsing in favor of deterministic database lookups.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — review-question