managing-launchdarkly
Warn
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines shell scripts that interpolate positional parameters directly into command strings within the ld_api helper function.
- Evidence: Variables like PROJECT_KEY and ENV_KEY are assigned from $1 and $2 and then passed to the ld_api function where they are used in a curl command string.
- Risk: This interpolation allows for potential shell command injection if the input contains expansion characters like $(...) or backticks.
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to the LaunchDarkly API to retrieve and manage feature flags.
- Evidence: The ld_api function uses curl to communicate with https://app.launchdarkly.com/api/v2.
- Note: This involves a well-known service and is a core part of the skill's intended functionality.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by reading and displaying untrusted data from an external service.
- Ingestion points: LaunchDarkly API responses fetched in discovery and analysis phases (SKILL.md).
- Boundary markers: Absent; data from the API is processed by jq and printed directly to the output.
- Capability inventory: The skill has the ability to execute shell commands via curl and jq.
- Sanitization: No evidence of data sanitization or escaping before the ingested content is presented to the agent context.
Audit Metadata