method-figure
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local command-line tools using the
subprocessmodule inscripts/run_spiral.pyandscripts/render_condition.py. These calls are used to execute thegeminiandcodexCLIs for image transcription and headless Chrome or Chromium for SVG-to-PNG rasterization. Whilescripts/run_spiral.pyallows for a configurable command via the--gemini-cmdargument, it employsshlex.splitfor argument parsing and avoids the use ofshell=True, significantly reducing the risk of shell injection. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user-supplied JSON data (
method_figure_brief.json). To mitigate potential injection risks, it implements the following evidence chain: 1. Ingestion points: The brief is processed bycompile_brief.py. 2. Boundary markers: Prompt templates utilize strict 'TEXT IS LOCKED' headers and structural delimiters to isolate instructions from data. 3. Capability inventory: The skill can execute local commands, write files to designated output directories, and call image generation tools. 4. Sanitization: It enforces strict schema validation throughvalidate_blueprint.pyand deterministic traceability checks incompile_brief.py, ensuring only authored content is used in the rendering process.
Audit Metadata