managing-grpc
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses bash scripts to orchestrate interactions with gRPC services. It executes standard CLI tools including
grpcurl,dig,nslookup, andjqto perform service discovery and diagnostics. - [PROMPT_INJECTION]: The skill contains an indirect injection surface where metadata (service and method names) retrieved from a remote gRPC server is used to construct subsequent shell commands.
- Ingestion points: Remote gRPC service and method names retrieved via reflection in Phase 1 (SKILL.md).
- Boundary markers: Absent; server-provided names are interpolated into shell command strings.
- Capability inventory: Shell execution of
grpcurland network utilities (dig,nslookup) in SKILL.md. - Sanitization: The scripts use parsing tools like
grep,awk, andtrwhich provide some implicit filtering, but do not perform explicit validation of gRPC metadata for shell injection characters.
Audit Metadata