conformetry-validate
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, including
nx run,conformetry validate,conformetry templates, andconformetry instances. These are necessary for the skill's documented functionality of validating code against templates. - [EXTERNAL_DOWNLOADS]: The documentation references external resources and examples hosted on a GitHub repository (
github.com/Organizzolini/codebase). These links point to the vendor's own repository and are used for documentation purposes. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon the output of the
conformetrytool. This creates a surface for indirect prompt injection if the tool's output (derived from the codebase) contains adversarial content intended to manipulate the agent's code-fixing behavior. - Ingestion points: Conformance reports generated by the
conformetry validatecommand (SKILL.md). - Boundary markers: None explicitly defined in the prompt instructions to isolate tool output.
- Capability inventory: File writing (implied remediation), shell command execution (
nx,conformetry). - Sanitization: No specific sanitization or validation of the report content is mentioned before the agent is instructed to "Read the Fix line" and apply changes.
- [DYNAMIC_EXECUTION]: The documentation specifies that comparison for Python (.py) and Jupyter notebook (.ipynb) files is performed by spawning a
python3subprocess. This is a standard architectural feature of the conformetry tool for cross-language support.
Audit Metadata