huashu-agent-swarm

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The monitoring dashboard (scripts/dashboard.py) is configured to listen on all network interfaces (0.0.0.0) by default. It provides a web interface with a command input field that sends data to the /api/input endpoint. This endpoint writes the input directly to HUMAN_INPUT.md without any authentication or validation. Because the agents are programmed to execute the contents of this file, this creates a remote command execution (RCE) vulnerability.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits a high-risk surface for indirect prompt injection:
  • Ingestion points: Agents are instructed in references/agent-prompt-template.md to read and prioritize instructions from HUMAN_INPUT.md, and to monitor TASKS.md and git log for coordination.
  • Boundary markers: There are no boundary markers or instructions to treat external data as untrusted. The prompt explicitly says "优先执行其中的指令" (prioritize executing the instructions).
  • Capability inventory: Each agent runs with --dangerously-skip-permissions, granting it full access to the shell, filesystem, and networking.
  • Sanitization: No sanitization or validation is performed on the data ingested from the external control files.
  • [DATA_EXFILTRATION]: The web dashboard exposes the project's internal state, including the full git log, the contents of TASKS.md, and real-time execution logs for every agent. Since the dashboard lacks authentication and binds to 0.0.0.0, sensitive information in the repository or logs is accessible to anyone on the network.
  • [DYNAMIC_EXECUTION]: The core mechanism in scripts/agent_loop.sh involves passing the AI model instructions that allow it to dynamically generate and execute shell commands without human oversight. When combined with the unauthenticated network input channel, this creates a significant security risk to the host environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — huashu-agent-swarm