Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn3 providerslatest audit Aug 30, 2026
Independent checks from skills.sh's audit partners.
The skill provides powerful automated compliance testing by running AI agents in sandboxed environments. While it includes several security safeguards such as path sanitization and restricted command execution during setup, it relies on subprocess calls to external binaries and dynamic code generation via LLMs. The use of shell commands during scenario setup and the reliance on LLM-generated YAML for configuration introduces a moderate risk of command injection or unexpected behavior if the LLM output is not perfectly formed or is influenced by adversarial skill content.
Detected behaviors
1 alert: gptAnomaly
No issues