helixa
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/helixa-search.shscript is vulnerable to command injection because it interpolates user-supplied arguments directly into a Python command string. Specifically, the expressionquery=$(python3 -c "import urllib.parse; print(urllib.parse.quote('$1'))" ...)allows an attacker to break out of the single-quoted Python string literal and execute arbitrary code if the input contains a single quote. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user-generated content (agent names, narratives, and traits) from the Helixa API, which can influence the agent's behavior.
- Ingestion points: Profile data in
scripts/helixa-agent.shand search results inscripts/helixa-search.sh. - Capability inventory: The skill allows network requests, shell execution, and Node.js wallet operations.
- Boundary markers:
SKILL.mdincludes a warning section advising users to treat API data as untrusted, but no technical enforcement is present. - Sanitization: No programmatic validation or sanitization is performed on the JSON values before they are returned to the agent context.
- [DYNAMIC_EXECUTION]: The skill utilizes Python at runtime for formatting and utility tasks.
- Evidence:
scripts/check-cred.shpipes remote API output directly topython3 -m json.toolfor JSON formatting. - Analysis: While flagged by automated scanners as a piped execution pattern, this specific usage of
json.toolis for data formatting. However, the reliance on piping external data to an interpreter increases the attack surface. - [REMOTE_CODE_EXECUTION]: Automated scanners detected a piped interpreter pattern in
scripts/check-cred.shwherecurloutput is sent topython3. While the script specifically invokes thejson.toolmodule, this pattern is generally discouraged as it relies on the safety of the remote API response.
Recommendations
- HIGH: Downloads and executes remote code from: https://api.helixa.xyz/api/v2/cred/${AGENT_ID} - DO NOT USE without thorough review
Audit Metadata