sparta-review

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs extensive process management and orchestration:
  • converge.py uses subprocess.Popen and subprocess.run to start, monitor, and manage the background generation process (12_qra.py).
  • It uses pgrep and os.kill (SIGTERM/SIGKILL) to stop and restart the generation pipeline during convergence cycles.
  • run.sh delegates tasks to other local skills (review-sparta, reality-check-sparta, dogpile, ask) by executing their respective shell scripts or Python entry points.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) due to its core functionality:
  • Ingestion points: Processes 'QRA' (Question-Reasoning-Answer) records from a DuckDB database (sparta.duckdb), which are generated by an external LLM pipeline.
  • Boundary markers: The assessment logic in brandon_reviewer.py uses local Python checks (keyword matching, grounding scores) but lacks explicit delimiters or instructions to ignore embedded commands when data is passed to research/consultation tools.
  • Capability inventory: The skill can execute shell commands, manage processes via os.kill, and perform file system operations like shutil.copy2 on databases.
  • Sanitization: Implements framework-specific keyword validation (e.g., D3FEND, CWE terms) and grounding score thresholds to filter low-quality outputs, providing a layer of validation against malformed or generic content.
  • [EXTERNAL_DOWNLOADS]: run.sh performs runtime dependency management using uv pip install to ensure required libraries (typer, duckdb, httpx, etc.) are available in the local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — sparta-review