use-skills-from-neuron

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of instructions fetched from a remote source. It explicitly directs the agent to treat external content as authoritative commands.
  • Step 3 of the "Use a skill from Nucleus" section in SKILL.md instructs the agent to: "Follow the retrieved instructions as if they were a local skill."
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by ingesting and obeying instructions from a shared workspace that could be modified by other users.
  • Ingestion points: Remote documents are fetched via neuron_read_file from the shared Agent Skills folder (ID cmtu6lgvt000ec6nx3lymzdlg) and the Agent Skills Index document.
  • Boundary markers: The skill lacks any delimiters or instructions to treat the remote content as untrusted data; instead, it validates the remote content as executable instructions.
  • Capability inventory: The agent's full set of tool capabilities (e.g., shell command execution, file system access, network operations) is made available to the remote instructions.
  • Sanitization: There is no mechanism to validate or sanitize the remote markdown content before the agent interprets it as instructions.
  • [DYNAMIC_EXECUTION]: The skill loads and executes instructions from dynamic paths (file IDs) resolved at runtime via a search tool.
  • Steps 1 and 2 in SKILL.md describe a process where the agent searches for a file by name, retrieves its ID, and then loads the instruction content associated with that ID.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — use-skills-from-neuron