blog
Fail
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/blog.shscript identifies modified or new executable files within thebin/directory of the repository it is analyzing. It then executes these binaries with the--helpflag to capture their output for the blog post. This allows for the execution of untrusted code from the repository being processed. - Evidence:
for bin in $(echo "$DIFF_OUTPUT" | grep -E '^\+\+\+ b/bin/' | sed 's|^\+\+\+ b/||'); do if [[ -x "$bin" ]] && "$bin" --help >/dev/null 2>&1; then ... "$bin" --help > "$DEST" 2>&1. - [DYNAMIC_EXECUTION]: The script dynamically creates a TypeScript file at
/tmp/blog-write-row.tsusing a heredoc template andsedfor path substitution. It then executes this generated code using thebunruntime to interface with the SQLite database. - Evidence:
cat > /tmp/blog-write-row.ts <<'TSFILE' ... bun /tmp/blog-write-row.ts. - [DATA_EXFILTRATION]: The skill provides two mechanisms for data exposure. The
--serveflag launches a Python HTTP server bound to0.0.0.0on port 8087, exposing the contents of the demo root (which contains artifacts and diff summaries) to the entire network. The--publishflag usesrsyncto synchronize the demo root directory to a remote host specified by theARC_DEMO_HOSTenvironment variable. - Evidence:
python3 -m http.server "$PORT" --bind 0.0.0.0 -d "$DEMO_ROOT"andrsync -av --delete "$DEMO_ROOT/" "${ARC_DEMO_HOST}". - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted data directly from
git diffoutputs. This data is interpolated into the blog body and metadata (HTML comments) without sanitization or clear boundary instructions, which could influence the behavior of the agent when drafting or reviewing the content. - Ingestion points:
scripts/blog.shcapturesgit diffandgit diff --stat(file name:scripts/blog.sh). - Boundary markers: The data is wrapped in backticks (diff-stat) and HTML comments, but no instructions are provided to the agent to ignore embedded malicious prompts.
- Capability inventory: The skill can execute shell commands, run
bunscripts, start network servers, and performrsyncoperations. - Sanitization: The script uses a
nodestringify helper to escape values for JSON, but the raw text content is still processed as natural language by the agent.
Recommendations
- AI detected serious security threats
Audit Metadata