skills/broomva/skills/persist/Gen Agent Trust Hub

persist

Warn

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The _spawn_agent function in scripts/persist.py invokes subprocess.run with shell=True. The command string is constructed using direct string replacement of the prompt file's content into a template (agent_cmd.replace('{}', prompt_text)). This allows any shell metacharacters in the prompt file to be executed by the shell.\n- [DYNAMIC_EXECUTION]: The skill generates and executes shell commands at runtime where a significant portion of the command string is sourced from a file (PROMPT.md) that is intended to be updated by an AI agent throughout the loop. This dynamic construction creates a high-risk execution path for data-driven payloads.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect instructions being executed as commands:\n
  • Ingestion points: Prompt data is read from the file system by scripts/persist.py before being interpolated into a shell command.\n
  • Boundary markers: The skill does not use delimiters or robust quoting to prevent prompt content from escaping the intended command context.\n
  • Capability inventory: The script has the capability to run arbitrary shell commands with the user's permissions.\n
  • Sanitization: No escaping or validation is applied to the prompt content before it is processed in the shell environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 7, 2026, 03:12 PM
Security Audit — agent-trust-hub — persist