python

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents command execution via subprocess.run but strictly enforces safe practices. It explicitly teaches using list-based arguments instead of shell strings (shell=True) and implements an ALLOWED_PROGRAMS whitelist to prevent arbitrary command execution. The occurrence of rm -rf / in references/threat-model.md and SKILL.md is correctly identified as an educational example of what to prevent, rather than a malicious instruction.
  • [DATA_EXFILTRATION]: The skill promotes secure data handling by instructing the agent to load secrets from environment variables rather than hardcoding them. It also provides robust path containment logic using pathlib's is_relative_to to prevent path traversal attacks.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for processing untrusted data (Pydantic models for user creation). However, the instructions focus entirely on strict schema validation, type checking, and regex-based sanitization of that data, which serves as a mitigation for injection attacks.
  • [DYNAMIC_EXECUTION]: While the skill mentions pickle in the threat model, it correctly identifies it as a high-risk anti-pattern for untrusted data and provides a RestrictedUnpickler implementation as a security example for legacy support scenarios.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:54 PM
Security Audit — agent-trust-hub — python