Ruby
Fail
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The ruby.sh script is vulnerable to shell command injection when executing Ruby commands on remote machines (fuji and junkpile).
- Evidence: The functions run_fuji and run_junkpile in ruby.sh use SSH to execute commands: ssh f "$FUJI_RUBY $" and ssh j "$JUNKPILE_RUBY $".
- The use of "$*" inside the SSH command string concatenates all arguments into a single string that is passed to and interpreted by the remote shell. This allows for the injection of arbitrary shell commands via metacharacters like semicolons (;), ampersands (&), or subshell invocations ($()).
- Impact: This allows an attacker to execute arbitrary code on the remote target machines by manipulating the arguments passed to the Ruby skill.
Recommendations
- AI detected serious security threats
Audit Metadata