crabbox
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to execute shell commands using the
crabboxCLI, such ascrabbox job run detectedandcrabbox run --id <slug> -- <command>. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and acts upon repository configuration files (
crabbox.yamlor.crabbox.yaml), which are untrusted data sources. 1. Ingestion points: Detection ofcrabbox.yamlor.crabbox.yamlin the repository root. 2. Boundary markers: Absent; the skill relies on the agent's manual inspection of the configuration content. 3. Capability inventory: ThecrabboxCLI provides capabilities for remote shell command execution and SSH access. 4. Sanitization: No programmatic sanitization or schema validation of the configuration file is defined.
Audit Metadata