review-readme

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The main script review_readme.py uses subprocess.run() to execute shell commands that invoke the run.sh script of a composed ask skill. This is used to pass data to the LLM oracle via command-line arguments, including user-supplied parameters like the Chrome tab ID.
  • [DATA_EXFILTRATION]: The skill reads the content of local README files and transmits them to an external LLM oracle (webkimi) through the composed ask skill. While this is the intended functionality, it involves sending local filesystem data to a remote service.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from the README file being audited and interpolates it directly into the prompt bundle sent to the oracle. A malicious README could contain instructions designed to override the review rubric and force a false PASS verdict.
  • [EXTERNAL_DOWNLOADS]: The uv.lock file contains references to multiple Python packages with suspicious, non-existent future version numbers and upload timestamps (e.g., typer@0.26.3, rich@15.0.0, pygments@2.20.0 with dates in 2025 and 2026). This deceptive metadata suggests a potential supply chain risk or a compromised configuration environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — review-readme