code-reproduction

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests and processes untrusted files from external repositories during its survey phase, which creates a potential surface for indirect prompt injection.
  • Ingestion points: The survey.py script reads text files from a repository cloned into /tmp/repro/.
  • Boundary markers: The skill does not currently implement specific boundary markers or 'ignore' instructions for the content it reads.
  • Capability inventory: The skill possesses file-writing capabilities (for reports) and command execution (for git/hardware probes), but it does not execute the contents of the surveyed repository.
  • Sanitization: The skill uses standard regex for analysis and json.dumps for output, providing basic protection against data confusion.
  • [COMMAND_EXECUTION]: The tool utilizes subprocess.run to interact with system utilities.
  • Evidence: probe.py calls nvidia-smi for hardware discovery, and survey.py calls git for metadata extraction.
  • Safety: These calls use argument lists rather than shell strings, avoiding shell injection vulnerabilities, and are restricted to specific, necessary tools.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with external resources as part of its primary function.
  • Evidence: It clones repositories using git clone and the test suite fetches data from GitHub via urllib.request.urlopen.
  • Scope: These downloads are directed at well-known services (GitHub) and are required for the skill's stated purpose.
  • [DATA_EXFILTRATION]: The host probe mechanism checks for the presence of environment variables.
  • Safeguard: The author has implemented a specific safeguard in probe.py (probe_env_vars function) that only records a boolean value indicating if a secret is set, explicitly preventing the exfiltration of actual credential values.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 06:54 AM
Security Audit — agent-trust-hub — code-reproduction