review-readme
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The main script
review_readme.pyusessubprocess.run()to execute shell commands that invoke therun.shscript of a composedaskskill. This is used to pass data to the LLM oracle via command-line arguments, including user-supplied parameters like the Chrome tab ID. - [DATA_EXFILTRATION]: The skill reads the content of local README files and transmits them to an external LLM oracle (
webkimi) through the composedaskskill. While this is the intended functionality, it involves sending local filesystem data to a remote service. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from the README file being audited and interpolates it directly into the prompt bundle sent to the oracle. A malicious README could contain instructions designed to override the review rubric and force a false PASS verdict.
- [EXTERNAL_DOWNLOADS]: The
uv.lockfile contains references to multiple Python packages with suspicious, non-existent future version numbers and upload timestamps (e.g.,typer@0.26.3,rich@15.0.0,pygments@2.20.0with dates in 2025 and 2026). This deceptive metadata suggests a potential supply chain risk or a compromised configuration environment.
Audit Metadata