managing-chroma
Fail
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The Phase 2 analysis script in
SKILL.mdcontains an unsafe string interpolation vulnerability. The shell variable$COLLECTION(derived from command-line arguments) is embedded directly into a Python script executed viapython3 -c. A malicious user could provide a collection name designed to escape the Python string and execute arbitrary code. - Evidence: The script uses
if c['name'] == '$COLLECTION':inside a double-quoted bash string passed to the Python interpreter. - [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection by processing and displaying untrusted data from the vector database.
- Ingestion points: The Phase 2 script in
SKILL.mdfetchesdocumentsandmetadatasfrom the/api/v1/collections/$COLL_ID/getendpoint. - Boundary markers: Absent. The skill output does not use delimiters or warnings to separate database content from agent instructions.
- Capability inventory: The skill has access to shell execution (
curl) and Python interpretation. - Sanitization: Absent. Document contents and metadata are printed directly to the output without filtering or escaping, allowing malicious instructions stored in the database to influence agent behavior.
Recommendations
- AI detected serious security threats
Audit Metadata