taxonomy
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill frequently invokes other agent tools via
subprocess.run, specifically targeting the/memoryskill for database operations. - [COMMAND_EXECUTION]:
taxonomy.pydynamically loads and executes internal logic from the/memoryskill usingimportlib.util.spec_from_file_location, which bypasses standard import safety checks. - [COMMAND_EXECUTION]: The
taxonomy_sweep.pyandtrain_bridge_text_classifier.pyscripts utilizejoblib.loadto deserialize local model files, a pattern that can lead to arbitrary code execution if model files are tampered with. - [EXTERNAL_DOWNLOADS]:
taxonomy.pycontains a self-repair mechanism that attempts to runpip install typerat runtime if the dependency is missing, bypassing centralized package management. - [CREDENTIALS_UNSAFE]: A hardcoded development API key (
sk-dev-proxy-123) is included intaxonomy.pyas a default fallback for the local LLM proxy service. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Untrusted content ingested via the
extractorsweepcommands is interpolated directly into LLM prompts without sanitization or protective boundary markers. This vulnerability is significant because the skill possesses high-level capabilities, including filesystem access (Read/Write) and shell command execution (Bash).
Audit Metadata