course-diff

Warn

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The shell commands defined in Steps 1 and 2, including cd, git log, and git show, interpolate user-supplied variables ({slug}, {v1}, {v2}) directly into the execution string. This pattern is susceptible to shell command injection if a malicious user provides inputs containing shell metacharacters (such as semicolons, pipes, or backticks) to execute unauthorized commands.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection (Category 8) by processing untrusted data from the repository history.
  • Ingestion points: The contents of course.json files are retrieved from git history and passed to a secondary agent for analysis.
  • Boundary markers: Absent. There are no delimiters or instructions provided to the changelog-generator agent to distinguish between data and instructions within the JSON files.
  • Capability inventory: The skill can execute shell commands (git), write to the local filesystem (both in /tmp and the docs/ directory), and invoke other agent skills.
  • Sanitization: No validation, escaping, or filtering is applied to the content retrieved from the course files before it is processed by the agent pipeline.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 17, 2026, 12:16 AM