paper-prototype
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes live data from external APIs, databases, and production files, which creates an attack surface for indirect prompt injection. Ingestion points: Step 2 involves acquiring real raw input from external APIs, live DB queries, and production files. Boundary markers: No delimiters or instructions are provided to the subagent to distinguish between data and instructions. Capability inventory: The agent is authorized to use curl, jq, sqlite3, and grep, and can write various file types to disk. Sanitization: There is no requirement for validation or sanitization of the external data before processing.
- [COMMAND_EXECUTION]: The instructions explicitly permit the use of shell one-liners and command-line utilities such as curl, sqlite3, and jq to interact with live production systems for data acquisition and movement.
Audit Metadata