skills/connorads/dotfiles/inspo/Gen Agent Trust Hub

inspo

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PERSISTENCE]: The shots subcommand in scripts/inspo.py is vulnerable to path traversal during file writing operations.
  • Evidence: The script constructs a local cache path using the user-supplied slug argument without any sanitization or validation: name=f"captures/{slug}/{VARIANTS[variant][0]}". This path is then used with path.parent.mkdir() and path.write_bytes().
  • Impact: A malicious slug containing directory traversal sequences (e.g., ../../) could be used to create directories and write files outside of the intended cache directory (~/.cache/inspo). While the specific filenames are restricted by hardcoded variants (e.g., hero.1440.webp), this lack of sanitization allows unauthorized filesystem manipulation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes large amounts of natural language data from a third-party archive that may be influenced by external actors.
  • Ingestion points: The get_screen, search_screens, and recommend tools return 'autopsy' and 'northstar' fields containing hundreds of words of design analysis.
  • Boundary markers: No explicit delimiters or instructions are used to separate this external content from the agent's system instructions.
  • Capability inventory: The agent has the ability to write to the filesystem and make network requests via the provided scripts.
  • Sanitization: Natural language fields are passed directly to the agent without filtering or escaping.
  • [EXTERNAL_DOWNLOADS]: The skill regularly fetches content from remote servers.
  • Evidence: scripts/inspo.py makes network requests to https://inspomcp.dev/api/mcp for metadata and to https://0nme3pk5am3urwa9.public.blob.vercel-storage.com for image assets. The latter is a well-known service provided by Vercel.
  • [COMMAND_EXECUTION]: The skill includes functionality for executing system-level commands.
  • Evidence: The test suite tests/test_inspo.py uses subprocess.run to execute the inspo.py script as a separate process to verify CLI behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 10:39 PM
Security Audit — agent-trust-hub — inspo