fr-analysis

Warn

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documentation states that it automatically detects and parses 'Binary pickle' payloads within the flight-recorder dumps. The use of Python's pickle module for deserializing data from external files (provided via the --fr-path argument) is inherently unsafe and can allow for arbitrary code execution if a maliciously crafted dump file is processed.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted data from external files and can pass it to an LLM via the --llm-analyze flag.
  • Ingestion points: Data is loaded from the directory or file specified by the --fr-path argument.
  • Boundary markers: The documentation does not mention the use of delimiters or specific instructions to the LLM to ignore embedded commands within the ingested log data.
  • Capability inventory: The skill is designed to run as a CLI tool (scripts/fr_attribution.py) or programmatic API, which the agent can execute. While the script itself focuses on analysis, it is part of a feedback loop for distributed training management.
  • Sanitization: There is no evidence of sanitization or filtering of the content extracted from the FR dumps before it is passed to the LLM.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 3, 2026, 05:27 PM
Security Audit — agent-trust-hub — fr-analysis