managing-chroma

Fail

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The Phase 2 analysis script in SKILL.md contains an unsafe string interpolation vulnerability. The shell variable $COLLECTION (derived from command-line arguments) is embedded directly into a Python script executed via python3 -c. A malicious user could provide a collection name designed to escape the Python string and execute arbitrary code.
  • Evidence: The script uses if c['name'] == '$COLLECTION': inside a double-quoted bash string passed to the Python interpreter.
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection by processing and displaying untrusted data from the vector database.
  • Ingestion points: The Phase 2 script in SKILL.md fetches documents and metadatas from the /api/v1/collections/$COLL_ID/get endpoint.
  • Boundary markers: Absent. The skill output does not use delimiters or warnings to separate database content from agent instructions.
  • Capability inventory: The skill has access to shell execution (curl) and Python interpretation.
  • Sanitization: Absent. Document contents and metadata are printed directly to the output without filtering or escaping, allowing malicious instructions stored in the database to influence agent behavior.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 23, 2026, 11:47 AM
Security Audit — agent-trust-hub — managing-chroma