use-skills-from-neuron
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of instructions fetched from a remote source. It explicitly directs the agent to treat external content as authoritative commands.
- Step 3 of the "Use a skill from Nucleus" section in
SKILL.mdinstructs the agent to: "Follow the retrieved instructions as if they were a local skill." - [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by ingesting and obeying instructions from a shared workspace that could be modified by other users.
- Ingestion points: Remote documents are fetched via
neuron_read_filefrom the sharedAgent Skillsfolder (IDcmtu6lgvt000ec6nx3lymzdlg) and theAgent Skills Indexdocument. - Boundary markers: The skill lacks any delimiters or instructions to treat the remote content as untrusted data; instead, it validates the remote content as executable instructions.
- Capability inventory: The agent's full set of tool capabilities (e.g., shell command execution, file system access, network operations) is made available to the remote instructions.
- Sanitization: There is no mechanism to validate or sanitize the remote markdown content before the agent interprets it as instructions.
- [DYNAMIC_EXECUTION]: The skill loads and executes instructions from dynamic paths (file IDs) resolved at runtime via a search tool.
- Steps 1 and 2 in
SKILL.mddescribe a process where the agent searches for a file by name, retrieves its ID, and then loads the instruction content associated with that ID.
Audit Metadata