dym-setup-guardrail-cli
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill includes a Python script in section 5 that is executed via a heredoc pattern (`python3
- <<'PY'
). This script performs automated modifications to a local configuration file (.harness/poc-vendor-neutral/policy.yaml`) using regular expressions. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its data ingestion points. Ingestion points: The
claude-hookmode inSKILL.mdreads JSON tool inputs from stdin, and thepathandfilesmodes process file contents from the repository. Boundary markers: No delimiters or safety instructions are present to prevent the agent from following instructions embedded within the validated data. Capability inventory: The skill executes shell commands viapython3andbash. Sanitization: No specific sanitization or filtering of the ingested content is described before processing. - [COMMAND_EXECUTION]: The skill invokes multiple internal scripts and shell commands, including
python3 .harness/poc-vendor-neutral/bin/llmwiki-validate.py,gen-converters.py,demo.sh, andtest-broad.sh. These operations are used for the skill's primary function of content validation and self-testing.
Audit Metadata