method-figure

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local command-line tools using the subprocess module in scripts/run_spiral.py and scripts/render_condition.py. These calls are used to execute the gemini and codex CLIs for image transcription and headless Chrome or Chromium for SVG-to-PNG rasterization. While scripts/run_spiral.py allows for a configurable command via the --gemini-cmd argument, it employs shlex.split for argument parsing and avoids the use of shell=True, significantly reducing the risk of shell injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied JSON data (method_figure_brief.json). To mitigate potential injection risks, it implements the following evidence chain: 1. Ingestion points: The brief is processed by compile_brief.py. 2. Boundary markers: Prompt templates utilize strict 'TEXT IS LOCKED' headers and structural delimiters to isolate instructions from data. 3. Capability inventory: The skill can execute local commands, write files to designated output directories, and call image generation tools. 4. Sanitization: It enforces strict schema validation through validate_blueprint.py and deterministic traceability checks in compile_brief.py, ensuring only authored content is used in the rendering process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 08:02 PM
Security Audit — agent-trust-hub — method-figure