fresh-deploy-friction
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/Dockerfilefetches thebunruntime installer fromhttps://bun.sh/installand executes it via a shell pipe. This is an expected setup step for the target environment using a well-known service. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the execution of instructions and scripts directly from external, potentially untrusted repositories to simulate user installation. This introduces a vulnerability to indirect prompt injection.
- Ingestion points: Repository content and installation documentation (READMEs) mounted or cloned into the container at
/src/<repo>. - Boundary markers: No explicit markers or warnings to ignore embedded instructions are used when processing external command strings.
- Capability inventory: The agent has the ability to execute shell commands (
docker exec), manage files, and access the network within the container. - Sanitization: There is no sanitization of the command strings extracted from the repositories before they are passed to the
exectool. - [COMMAND_EXECUTION]: The
scripts/run.shutility allows for arbitrary command execution within the container viabash -lc. While contained, this capability can be leveraged by malicious code within a tested repository. - [DYNAMIC_EXECUTION]: The skill dynamically generates and executes shell commands and scripts at runtime using
docker execandcp-exec, which is the primary mechanism for its testing workflow. - [DATA_EXFILTRATION]: Sensitive API keys (e.g.,
ANTHROPIC_API_KEY,OPENROUTER_API_KEY) are forwarded into the container's environment to enable testing. This creates a risk where malicious code in a repository under test could attempt to read and exfiltrate these credentials.
Audit Metadata