sparta-review
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs extensive process management and orchestration:
converge.pyusessubprocess.Popenandsubprocess.runto start, monitor, and manage the background generation process (12_qra.py).- It uses
pgrepandos.kill(SIGTERM/SIGKILL) to stop and restart the generation pipeline during convergence cycles. run.shdelegates tasks to other local skills (review-sparta,reality-check-sparta,dogpile,ask) by executing their respective shell scripts or Python entry points.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) due to its core functionality:
- Ingestion points: Processes 'QRA' (Question-Reasoning-Answer) records from a DuckDB database (
sparta.duckdb), which are generated by an external LLM pipeline. - Boundary markers: The assessment logic in
brandon_reviewer.pyuses local Python checks (keyword matching, grounding scores) but lacks explicit delimiters or instructions to ignore embedded commands when data is passed to research/consultation tools. - Capability inventory: The skill can execute shell commands, manage processes via
os.kill, and perform file system operations likeshutil.copy2on databases. - Sanitization: Implements framework-specific keyword validation (e.g., D3FEND, CWE terms) and grounding score thresholds to filter low-quality outputs, providing a layer of validation against malformed or generic content.
- [EXTERNAL_DOWNLOADS]:
run.shperforms runtime dependency management usinguv pip installto ensure required libraries (typer,duckdb,httpx, etc.) are available in the local environment.
Audit Metadata