skills/bankrbot/skills/helixa/Gen Agent Trust Hub

helixa

Fail

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/helixa-search.sh script is vulnerable to command injection because it interpolates user-supplied arguments directly into a Python command string. Specifically, the expression query=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$1'))" ...) allows an attacker to break out of the single-quoted Python string literal and execute arbitrary code if the input contains a single quote.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user-generated content (agent names, narratives, and traits) from the Helixa API, which can influence the agent's behavior.
  • Ingestion points: Profile data in scripts/helixa-agent.sh and search results in scripts/helixa-search.sh.
  • Capability inventory: The skill allows network requests, shell execution, and Node.js wallet operations.
  • Boundary markers: SKILL.md includes a warning section advising users to treat API data as untrusted, but no technical enforcement is present.
  • Sanitization: No programmatic validation or sanitization is performed on the JSON values before they are returned to the agent context.
  • [DYNAMIC_EXECUTION]: The skill utilizes Python at runtime for formatting and utility tasks.
  • Evidence: scripts/check-cred.sh pipes remote API output directly to python3 -m json.tool for JSON formatting.
  • Analysis: While flagged by automated scanners as a piped execution pattern, this specific usage of json.tool is for data formatting. However, the reliance on piping external data to an interpreter increases the attack surface.
  • [REMOTE_CODE_EXECUTION]: Automated scanners detected a piped interpreter pattern in scripts/check-cred.sh where curl output is sent to python3. While the script specifically invokes the json.tool module, this pattern is generally discouraged as it relies on the safety of the remote API response.
Recommendations
  • HIGH: Downloads and executes remote code from: https://api.helixa.xyz/api/v2/cred/${AGENT_ID} - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 24, 2026, 04:45 AM
Security Audit — agent-trust-hub — helixa