managing-loggly

Fail

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The loggly_search shell function in SKILL.md uses string interpolation to embed the ${query} variable directly into a Python command executed via python3 -c. This pattern allows shell-to-Python command injection if the input contains malicious characters.- [REMOTE_CODE_EXECUTION]: Because the input is not sanitized before being placed into the Python script string, an attacker can craft a payload (e.g., using single quotes to break out of the string literal) to execute arbitrary Python code and subsequent system commands on the host system.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 23, 2026, 11:54 AM
Security Audit — agent-trust-hub — managing-loggly