fresh-deploy-friction

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/Dockerfile fetches the bun runtime installer from https://bun.sh/install and executes it via a shell pipe. This is an expected setup step for the target environment using a well-known service.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the execution of instructions and scripts directly from external, potentially untrusted repositories to simulate user installation. This introduces a vulnerability to indirect prompt injection.
  • Ingestion points: Repository content and installation documentation (READMEs) mounted or cloned into the container at /src/<repo>.
  • Boundary markers: No explicit markers or warnings to ignore embedded instructions are used when processing external command strings.
  • Capability inventory: The agent has the ability to execute shell commands (docker exec), manage files, and access the network within the container.
  • Sanitization: There is no sanitization of the command strings extracted from the repositories before they are passed to the exec tool.
  • [COMMAND_EXECUTION]: The scripts/run.sh utility allows for arbitrary command execution within the container via bash -lc. While contained, this capability can be leveraged by malicious code within a tested repository.
  • [DYNAMIC_EXECUTION]: The skill dynamically generates and executes shell commands and scripts at runtime using docker exec and cp-exec, which is the primary mechanism for its testing workflow.
  • [DATA_EXFILTRATION]: Sensitive API keys (e.g., ANTHROPIC_API_KEY, OPENROUTER_API_KEY) are forwarded into the container's environment to enable testing. This creates a risk where malicious code in a repository under test could attempt to read and exfiltrate these credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:52 PM
Security Audit — agent-trust-hub — fresh-deploy-friction