sparta-stress-test
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DATA_EXFILTRATION]: The script
scripts/harvest_skill_chains.pyscans and reads Claude CLI conversation transcripts stored in the user's home directory (~/.claude/projects/). This data is mined to extract training pairs for skill recommendation models. This represents a privacy risk as conversation transcripts often contain sensitive code, proprietary information, and internal queries. - [COMMAND_EXECUTION]: In
sparta_stress_test/conversation_steering.py, the function_execute_skill_chainexecutes other skills in the monorepo by calling theirrun.shscripts viasubprocess.run. The command accepts user-provided question text as an argument. While it uses the list-form execution, this pattern allows the skill to act as a dispatcher for arbitrary sibling tools. - [REMOTE_CODE_EXECUTION]: The skill uses
importlib.utilinsparta_stress_test/conversation_models.pyto dynamically load Python modules from filesystem paths computed at runtime (specifically targetingbackfill_chunk_control_edges.pyin the siblingmemoryproject). Dynamic loading from computed paths is a high-risk pattern that can be exploited if path construction is influenced by external input. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to
http://localhost:8604for Lean4 formal verification services and to an external LLM provider athttps://llm.chutes.ai/v1for inference tasks.
Audit Metadata