taxonomy

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently invokes other agent tools via subprocess.run, specifically targeting the /memory skill for database operations.
  • [COMMAND_EXECUTION]: taxonomy.py dynamically loads and executes internal logic from the /memory skill using importlib.util.spec_from_file_location, which bypasses standard import safety checks.
  • [COMMAND_EXECUTION]: The taxonomy_sweep.py and train_bridge_text_classifier.py scripts utilize joblib.load to deserialize local model files, a pattern that can lead to arbitrary code execution if model files are tampered with.
  • [EXTERNAL_DOWNLOADS]: taxonomy.py contains a self-repair mechanism that attempts to run pip install typer at runtime if the dependency is missing, bypassing centralized package management.
  • [CREDENTIALS_UNSAFE]: A hardcoded development API key (sk-dev-proxy-123) is included in taxonomy.py as a default fallback for the local LLM proxy service.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Untrusted content ingested via the extract or sweep commands is interpolated directly into LLM prompts without sanitization or protective boundary markers. This vulnerability is significant because the skill possesses high-level capabilities, including filesystem access (Read/Write) and shell command execution (Bash).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — taxonomy