code-reproduction
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill ingests and processes untrusted files from external repositories during its survey phase, which creates a potential surface for indirect prompt injection.
- Ingestion points: The
survey.pyscript reads text files from a repository cloned into/tmp/repro/. - Boundary markers: The skill does not currently implement specific boundary markers or 'ignore' instructions for the content it reads.
- Capability inventory: The skill possesses file-writing capabilities (for reports) and command execution (for git/hardware probes), but it does not execute the contents of the surveyed repository.
- Sanitization: The skill uses standard regex for analysis and
json.dumpsfor output, providing basic protection against data confusion. - [COMMAND_EXECUTION]: The tool utilizes
subprocess.runto interact with system utilities. - Evidence:
probe.pycallsnvidia-smifor hardware discovery, andsurvey.pycallsgitfor metadata extraction. - Safety: These calls use argument lists rather than shell strings, avoiding shell injection vulnerabilities, and are restricted to specific, necessary tools.
- [EXTERNAL_DOWNLOADS]: The skill interacts with external resources as part of its primary function.
- Evidence: It clones repositories using
git cloneand the test suite fetches data from GitHub viaurllib.request.urlopen. - Scope: These downloads are directed at well-known services (GitHub) and are required for the skill's stated purpose.
- [DATA_EXFILTRATION]: The host probe mechanism checks for the presence of environment variables.
- Safeguard: The author has implemented a specific safeguard in
probe.py(probe_env_varsfunction) that only records a boolean value indicating if a secret is set, explicitly preventing the exfiltration of actual credential values.
Audit Metadata