persist
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
_spawn_agentfunction inscripts/persist.pyinvokessubprocess.runwithshell=True. The command string is constructed using direct string replacement of the prompt file's content into a template (agent_cmd.replace('{}', prompt_text)). This allows any shell metacharacters in the prompt file to be executed by the shell.\n- [DYNAMIC_EXECUTION]: The skill generates and executes shell commands at runtime where a significant portion of the command string is sourced from a file (PROMPT.md) that is intended to be updated by an AI agent throughout the loop. This dynamic construction creates a high-risk execution path for data-driven payloads.\n- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect instructions being executed as commands:\n - Ingestion points: Prompt data is read from the file system by
scripts/persist.pybefore being interpolated into a shell command.\n - Boundary markers: The skill does not use delimiters or robust quoting to prevent prompt content from escaping the intended command context.\n
- Capability inventory: The script has the capability to run arbitrary shell commands with the user's permissions.\n
- Sanitization: No escaping or validation is applied to the prompt content before it is processed in the shell environment.
Audit Metadata