inspo
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMPERSISTENCEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PERSISTENCE]: The
shotssubcommand inscripts/inspo.pyis vulnerable to path traversal during file writing operations. - Evidence: The script constructs a local cache path using the user-supplied
slugargument without any sanitization or validation:name=f"captures/{slug}/{VARIANTS[variant][0]}". This path is then used withpath.parent.mkdir()andpath.write_bytes(). - Impact: A malicious slug containing directory traversal sequences (e.g.,
../../) could be used to create directories and write files outside of the intended cache directory (~/.cache/inspo). While the specific filenames are restricted by hardcoded variants (e.g.,hero.1440.webp), this lack of sanitization allows unauthorized filesystem manipulation. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes large amounts of natural language data from a third-party archive that may be influenced by external actors.
- Ingestion points: The
get_screen,search_screens, andrecommendtools return 'autopsy' and 'northstar' fields containing hundreds of words of design analysis. - Boundary markers: No explicit delimiters or instructions are used to separate this external content from the agent's system instructions.
- Capability inventory: The agent has the ability to write to the filesystem and make network requests via the provided scripts.
- Sanitization: Natural language fields are passed directly to the agent without filtering or escaping.
- [EXTERNAL_DOWNLOADS]: The skill regularly fetches content from remote servers.
- Evidence:
scripts/inspo.pymakes network requests tohttps://inspomcp.dev/api/mcpfor metadata and tohttps://0nme3pk5am3urwa9.public.blob.vercel-storage.comfor image assets. The latter is a well-known service provided by Vercel. - [COMMAND_EXECUTION]: The skill includes functionality for executing system-level commands.
- Evidence: The test suite
tests/test_inspo.pyusessubprocess.runto execute theinspo.pyscript as a separate process to verify CLI behavior.
Audit Metadata