agency-report-pdf
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a local Python script (
python3 ~/.claude/skills/agency/scripts/generate_agency_pdf.py) to generate reports and suggests runningpip3 install reportlabto install a required library. - [INDIRECT_PROMPT_INJECTION]: The skill extracts information from markdown files in the current working directory, which serves as a potential surface for indirect prompt injection.
- Ingestion points: Local markdown files matching patterns like
AGENCY-ONBOARD-*.mdandMARKETING-AUDIT*.md(SKILL.md, Step 1 and Step 2). - Boundary markers: Absent. The instructions do not define delimiters or provide warnings to disregard instructions inside the audit files.
- Capability inventory: The skill can write files (
agency_data.json) and execute shell commands (python3,pip3) (SKILL.md, Step 6 and Step 7). - Sanitization: The instructions recommend JSON escaping and schema validation for the output file but do not address the sanitization of input data extracted from the markdown files.
- [DYNAMIC_EXECUTION]: The skill creates a JSON file at runtime and passes it to a Python script for further processing and PDF rendering.
Audit Metadata