skill-lab

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a significant surface for Indirect Prompt Injection. It ingests untrusted natural language task descriptions (e.g., in gap_detector.py and gap_synthesizer.py) which are interpolated into LLM prompts to determine the architecture, dependencies, and metadata of new skills. These generated manifests are then used by scaffolder.py to create executable shell scripts.\n- [COMMAND_EXECUTION]: The skill performs dynamic script generation and execution as part of its primary workflow. scaffolder.py writes new run.sh files to the filesystem and sets them as executable. composer.py executes pipelines by calling multiple skill scripts via subprocess.run, passing user-controlled arguments. warm_pond.py executes a generated bash script inside a Docker container.\n- [EXTERNAL_DOWNLOADS]: The warm_pond.py script references the python:3.12-slim image from Docker Hub to provide an isolated environment for testing skill compositions. This reference to a well-known service is documented neutrally as a safe dependency for the skill's simulation environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — skill-lab