scillm

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The files batch.py, preflight.py, service.py, and vlm.py contain a hardcoded default API key 'sk-dev-proxy-123' assigned to the SCILLM_PROXY_KEY variable. This matches the 'sk-' pattern specified for sensitive credentials.
  • [COMMAND_EXECUTION]: The run.sh script facilitates the execution of internal Python tools via 'uv run', enabling local command execution within the agent's environment.
  • [DATA_EXFILTRATION]: The vlm.py script reads local image files, encodes them as base64 data URIs, and sends them to external LLM providers. If file paths are sourced from untrusted data, this mechanism could be used to exfiltrate sensitive local files.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection where malicious instructions could be embedded in the data processed by the LLM.
  • Ingestion points: Untrusted content can enter through user-defined prompts in batch.py and vlm.py, as well as from the contents of files or images processed by the VLM tool.
  • Boundary markers: There are no boundary markers or explicit instructions to the LLM to ignore potentially malicious content within the interpolated data.
  • Capability inventory: The skill has broad capabilities including network access to multiple LLM providers and the ability to read arbitrary local files via the Path API in vlm.py.
  • Sanitization: No sanitization or validation of the input prompts or paths is performed before they are passed to the completion engines.
  • [EXTERNAL_DOWNLOADS]: Fetches the scillm library from the author's GitHub repository as defined in the pyproject.toml dependencies.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — scillm