conformetry-validate

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, including nx run, conformetry validate, conformetry templates, and conformetry instances. These are necessary for the skill's documented functionality of validating code against templates.
  • [EXTERNAL_DOWNLOADS]: The documentation references external resources and examples hosted on a GitHub repository (github.com/Organizzolini/codebase). These links point to the vendor's own repository and are used for documentation purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon the output of the conformetry tool. This creates a surface for indirect prompt injection if the tool's output (derived from the codebase) contains adversarial content intended to manipulate the agent's code-fixing behavior.
  • Ingestion points: Conformance reports generated by the conformetry validate command (SKILL.md).
  • Boundary markers: None explicitly defined in the prompt instructions to isolate tool output.
  • Capability inventory: File writing (implied remediation), shell command execution (nx, conformetry).
  • Sanitization: No specific sanitization or validation of the report content is mentioned before the agent is instructed to "Read the Fix line" and apply changes.
  • [DYNAMIC_EXECUTION]: The documentation specifies that comparison for Python (.py) and Jupyter notebook (.ipynb) files is performed by spawning a python3 subprocess. This is a standard architectural feature of the conformetry tool for cross-language support.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:18 PM
Security Audit — agent-trust-hub — conformetry-validate