agency-report-pdf

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script (python3 ~/.claude/skills/agency/scripts/generate_agency_pdf.py) to generate reports and suggests running pip3 install reportlab to install a required library.
  • [INDIRECT_PROMPT_INJECTION]: The skill extracts information from markdown files in the current working directory, which serves as a potential surface for indirect prompt injection.
  • Ingestion points: Local markdown files matching patterns like AGENCY-ONBOARD-*.md and MARKETING-AUDIT*.md (SKILL.md, Step 1 and Step 2).
  • Boundary markers: Absent. The instructions do not define delimiters or provide warnings to disregard instructions inside the audit files.
  • Capability inventory: The skill can write files (agency_data.json) and execute shell commands (python3, pip3) (SKILL.md, Step 6 and Step 7).
  • Sanitization: The instructions recommend JSON escaping and schema validation for the output file but do not address the sanitization of input data extracted from the markdown files.
  • [DYNAMIC_EXECUTION]: The skill creates a JSON file at runtime and passes it to a Python script for further processing and PDF rendering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:11 AM
Security Audit — agent-trust-hub — agency-report-pdf