huashu-agent-swarm
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The monitoring dashboard (
scripts/dashboard.py) is configured to listen on all network interfaces (0.0.0.0) by default. It provides a web interface with a command input field that sends data to the/api/inputendpoint. This endpoint writes the input directly toHUMAN_INPUT.mdwithout any authentication or validation. Because the agents are programmed to execute the contents of this file, this creates a remote command execution (RCE) vulnerability. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits a high-risk surface for indirect prompt injection:
- Ingestion points: Agents are instructed in
references/agent-prompt-template.mdto read and prioritize instructions fromHUMAN_INPUT.md, and to monitorTASKS.mdandgit logfor coordination. - Boundary markers: There are no boundary markers or instructions to treat external data as untrusted. The prompt explicitly says "优先执行其中的指令" (prioritize executing the instructions).
- Capability inventory: Each agent runs with
--dangerously-skip-permissions, granting it full access to the shell, filesystem, and networking. - Sanitization: No sanitization or validation is performed on the data ingested from the external control files.
- [DATA_EXFILTRATION]: The web dashboard exposes the project's internal state, including the full
git log, the contents ofTASKS.md, and real-time execution logs for every agent. Since the dashboard lacks authentication and binds to0.0.0.0, sensitive information in the repository or logs is accessible to anyone on the network. - [DYNAMIC_EXECUTION]: The core mechanism in
scripts/agent_loop.shinvolves passing the AI model instructions that allow it to dynamically generate and execute shell commands without human oversight. When combined with the unauthenticated network input channel, this creates a significant security risk to the host environment.
Recommendations
- AI detected serious security threats
Audit Metadata