sparta-stress-test

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DATA_EXFILTRATION]: The script scripts/harvest_skill_chains.py scans and reads Claude CLI conversation transcripts stored in the user's home directory (~/.claude/projects/). This data is mined to extract training pairs for skill recommendation models. This represents a privacy risk as conversation transcripts often contain sensitive code, proprietary information, and internal queries.
  • [COMMAND_EXECUTION]: In sparta_stress_test/conversation_steering.py, the function _execute_skill_chain executes other skills in the monorepo by calling their run.sh scripts via subprocess.run. The command accepts user-provided question text as an argument. While it uses the list-form execution, this pattern allows the skill to act as a dispatcher for arbitrary sibling tools.
  • [REMOTE_CODE_EXECUTION]: The skill uses importlib.util in sparta_stress_test/conversation_models.py to dynamically load Python modules from filesystem paths computed at runtime (specifically targeting backfill_chunk_control_edges.py in the sibling memory project). Dynamic loading from computed paths is a high-risk pattern that can be exploited if path construction is influenced by external input.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to http://localhost:8604 for Lean4 formal verification services and to an external LLM provider at https://llm.chutes.ai/v1 for inference tasks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:38 AM
Security Audit — agent-trust-hub — sparta-stress-test