shaon

Fail

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The command shaon payroll payslip password --force-sensitive-output prints the user's account password in plaintext to standard output. If an AI agent executes this command, the password becomes part of the conversation context and transcript, creating a significant risk of credential exposure or exfiltration.
  • [DATA_EXFILTRATION]: The skill is designed to retrieve sensitive personal data, including payslips and salary information. There is an inherent risk that an agent could exfiltrate this data if prompted to summarized or send it to an external destination.
  • [COMMAND_EXECUTION]: The skill relies on a local CLI tool and shell scripts to interact with a real-world production portal under the user's identity.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection via the data it processes from the external portal. Ingestion points: Attendance reports and error messages from the Hilan portal. Boundary markers: No markers are used to separate fetched data from agent instructions. Capability inventory: The skill can execute shell commands and modify attendance records. Sanitization: No sanitization of content from the external portal is implemented.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 17, 2026, 05:36 AM
Security Audit — agent-trust-hub — shaon