fr-analysis
Warn
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documentation states that it automatically detects and parses 'Binary pickle' payloads within the flight-recorder dumps. The use of Python's
picklemodule for deserializing data from external files (provided via the--fr-pathargument) is inherently unsafe and can allow for arbitrary code execution if a maliciously crafted dump file is processed. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted data from external files and can pass it to an LLM via the
--llm-analyzeflag. - Ingestion points: Data is loaded from the directory or file specified by the
--fr-pathargument. - Boundary markers: The documentation does not mention the use of delimiters or specific instructions to the LLM to ignore embedded commands within the ingested log data.
- Capability inventory: The skill is designed to run as a CLI tool (
scripts/fr_attribution.py) or programmatic API, which the agent can execute. While the script itself focuses on analysis, it is part of a feedback loop for distributed training management. - Sanitization: There is no evidence of sanitization or filtering of the content extracted from the FR dumps before it is passed to the LLM.
Audit Metadata