course-diff
Warn
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The shell commands defined in Steps 1 and 2, including
cd,git log, andgit show, interpolate user-supplied variables ({slug},{v1},{v2}) directly into the execution string. This pattern is susceptible to shell command injection if a malicious user provides inputs containing shell metacharacters (such as semicolons, pipes, or backticks) to execute unauthorized commands. - [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) by processing untrusted data from the repository history.
- Ingestion points: The contents of
course.jsonfiles are retrieved from git history and passed to a secondary agent for analysis. - Boundary markers: Absent. There are no delimiters or instructions provided to the
changelog-generatoragent to distinguish between data and instructions within the JSON files. - Capability inventory: The skill can execute shell commands (
git), write to the local filesystem (both in/tmpand thedocs/directory), and invoke other agent skills. - Sanitization: No validation, escaping, or filtering is applied to the content retrieved from the course files before it is processed by the agent pipeline.
Audit Metadata