using-exe-dev

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use ssh and scp commands to perform VM lifecycle management, file transfers, and remote shell operations.- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to fetch documentation from external URLs (https://exe.dev/docs.md, https://exe.dev/docs/all.md) and facilitates interaction with remote VMs, creating an attack surface where untrusted data could influence agent behavior.
  • Ingestion points: Documentation URLs and output from remote SSH sessions on VMs.
  • Boundary markers: Absent; the instructions do not include specific delimiters to isolate external content from the agent's core instructions.
  • Capability inventory: The agent is granted capabilities to execute network-active shell commands (SSH, SCP).
  • Sanitization: Absent; there is no mention of validating or filtering content retrieved from the external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:30 PM