skills/a-canary/arc-skills/blog/Gen Agent Trust Hub

blog

Fail

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/blog.sh script identifies modified or new executable files within the bin/ directory of the repository it is analyzing. It then executes these binaries with the --help flag to capture their output for the blog post. This allows for the execution of untrusted code from the repository being processed.
  • Evidence: for bin in $(echo "$DIFF_OUTPUT" | grep -E '^\+\+\+ b/bin/' | sed 's|^\+\+\+ b/||'); do if [[ -x "$bin" ]] && "$bin" --help >/dev/null 2>&1; then ... "$bin" --help > "$DEST" 2>&1.
  • [DYNAMIC_EXECUTION]: The script dynamically creates a TypeScript file at /tmp/blog-write-row.ts using a heredoc template and sed for path substitution. It then executes this generated code using the bun runtime to interface with the SQLite database.
  • Evidence: cat > /tmp/blog-write-row.ts <<'TSFILE' ... bun /tmp/blog-write-row.ts.
  • [DATA_EXFILTRATION]: The skill provides two mechanisms for data exposure. The --serve flag launches a Python HTTP server bound to 0.0.0.0 on port 8087, exposing the contents of the demo root (which contains artifacts and diff summaries) to the entire network. The --publish flag uses rsync to synchronize the demo root directory to a remote host specified by the ARC_DEMO_HOST environment variable.
  • Evidence: python3 -m http.server "$PORT" --bind 0.0.0.0 -d "$DEMO_ROOT" and rsync -av --delete "$DEMO_ROOT/" "${ARC_DEMO_HOST}".
  • [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection because it ingests untrusted data directly from git diff outputs. This data is interpolated into the blog body and metadata (HTML comments) without sanitization or clear boundary instructions, which could influence the behavior of the agent when drafting or reviewing the content.
  • Ingestion points: scripts/blog.sh captures git diff and git diff --stat (file name: scripts/blog.sh).
  • Boundary markers: The data is wrapped in backticks (diff-stat) and HTML comments, but no instructions are provided to the agent to ignore embedded malicious prompts.
  • Capability inventory: The skill can execute shell commands, run bun scripts, start network servers, and perform rsync operations.
  • Sanitization: The script uses a node stringify helper to escape values for JSON, but the raw text content is still processed as natural language by the agent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 27, 2026, 01:03 AM
Security Audit — agent-trust-hub — blog