managing-loggly
Fail
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
loggly_searchshell function inSKILL.mduses string interpolation to embed the${query}variable directly into a Python command executed viapython3 -c. This pattern allows shell-to-Python command injection if the input contains malicious characters.- [REMOTE_CODE_EXECUTION]: Because the input is not sanitized before being placed into the Python script string, an attacker can craft a payload (e.g., using single quotes to break out of the string literal) to execute arbitrary Python code and subsequent system commands on the host system.
Recommendations
- AI detected serious security threats
Audit Metadata