dym-setup-guardrail-cli

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill includes a Python script in section 5 that is executed via a heredoc pattern (`python3
  • <<'PY'). This script performs automated modifications to a local configuration file (.harness/poc-vendor-neutral/policy.yaml`) using regular expressions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its data ingestion points. Ingestion points: The claude-hook mode in SKILL.md reads JSON tool inputs from stdin, and the path and files modes process file contents from the repository. Boundary markers: No delimiters or safety instructions are present to prevent the agent from following instructions embedded within the validated data. Capability inventory: The skill executes shell commands via python3 and bash. Sanitization: No specific sanitization or filtering of the ingested content is described before processing.
  • [COMMAND_EXECUTION]: The skill invokes multiple internal scripts and shell commands, including python3 .harness/poc-vendor-neutral/bin/llmwiki-validate.py, gen-converters.py, demo.sh, and test-broad.sh. These operations are used for the skill's primary function of content validation and self-testing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 06:23 AM