using-exe-dev
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use ssh and scp commands to perform VM lifecycle management, file transfers, and remote shell operations.- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch documentation from external URLs (https://exe.dev/docs.md, https://exe.dev/docs/all.md) and facilitates interaction with remote VMs, creating an attack surface where untrusted data could influence agent behavior.
- Ingestion points: Documentation URLs and output from remote SSH sessions on VMs.
- Boundary markers: Absent; the instructions do not include specific delimiters to isolate external content from the agent's core instructions.
- Capability inventory: The agent is granted capabilities to execute network-active shell commands (SSH, SCP).
- Sanitization: Absent; there is no mention of validating or filtering content retrieved from the external sources.
Audit Metadata