wizard
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads and interprets content from repository files (e.g.,
README.md,.env.example, and CI workflows) to identify necessary configuration steps. Malicious content in these files could influence the agent to generate deceptive instructions or phishing URLs within the wizard. - Ingestion points: Project documentation and configuration files specified in
SKILL.md. - Boundary markers: The skill does not utilize specific delimiters or instructions to isolate untrusted file content during processing.
- Capability inventory: The generated scripts can modify local
.envfiles, manage GitHub secrets via theghCLI, and open URLs in the system browser. - Sanitization: The template employs safe shell practices, such as
printf -vfor variable assignment and hidden input (read -rs) for secrets. - [DYNAMIC_EXECUTION]: The skill generates a functional bash script at runtime based on a template and AI-authored logic. This dynamically created code is intended for subsequent execution by the user, creating a new execution surface.
- [PRIVILEGE_ESCALATION]: The instructions direct the agent to grant execution permissions to the generated script using
chmod +x. While common for script generation tasks, this marks dynamically created content as executable.
Audit Metadata