neuromatrix
Warn
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides tools for executing arbitrary shell commands and processes within the provider runtime.
- Evidence: The
spawn_endpoint_clienttool allows the agent to execute a specifiedcommandwith providedargsandvariables. Examples inreferences/debugging-and-composition.mdshow the use of/bin/shto execute shell strings. - Evidence: The
start_interactive_sessiontool allows launching interactive processes in the session workspace, such as emulators or debugger instances. - [REMOTE_CODE_EXECUTION]: The primary purpose of the skill is to execute user-provided code (binaries, firmware, kernels) across various emulation backends.
- Evidence: The skill facilitates running binaries through backends including Unicorn, Qiling (userland binaries), QEMU (Linux user-mode and full-system), and Renode (MCU firmware).
- Evidence: The
import_artifact_to_workspacetool allows marking uploaded artifacts as executable (executable=true) before they are run by server-side tools. - [EXTERNAL_DOWNLOADS]: The skill uses a data plane that involves transferring potentially large files to and from external URLs.
- Evidence:
references/artifacts-jobs-endpoints.mddescribes a flow whererequest_uploadandrequest_downloadreturn dynamic HTTP URLs for moving artifacts usingcurlor similar tools. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from emulated targets which could influence the agent's behavior.
- Ingestion points: The agent reads data via
read_interactive_session(UART/stdout from targets),inspect_binary, andanalyze_artifact(SKILL.md). - Boundary markers: No explicit instructions are provided to the agent to treat emulation output or disassembly as untrusted or to use strict delimiters.
- Capability inventory: The skill has high-privilege capabilities including command execution (
spawn_endpoint_client) and file management (request_upload). - Sanitization: There is no mention of sanitizing or escaping the output from interactive sessions before the agent processes it.
Audit Metadata