drone-inspection-specialist

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run within references/gaussian-splatting-3d.md and reference.md to execute the colmap binary for Structure-from-Motion tasks and external Python scripts such as train.py, render.py, and convert_to_web.py for 3D reconstruction pipelines.
  • [DYNAMIC_EXECUTION]: Found in the 3D reconstruction implementation where shell commands are dynamically constructed and executed to run training and rendering scripts based on provided file paths.
  • [DATA_EXFILTRATION]: The FireAlertSystem class in references/fire-detection.md contains a send_to_dispatch method that utilizes the requests library to POST alert data, including GPS coordinates and temperatures, to a configurable external endpoint.
  • [EXTERNAL_DOWNLOADS]: The 3D visualization component in references/gaussian-splatting-3d.md generates HTML that fetches the Three.js library from the JSDelivr content delivery network (cdn.jsdelivr.net), a well-known and widely used service.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data, including drone video files, property imagery, and satellite data obtained via Firecrawl or WebFetch. While it uses standard ML frameworks (YOLO, COLMAP) for processing, these ingestion points represent an attack surface for potentially malicious artifacts.
  • Ingestion points: Video and image file paths in references/fire-detection.md and references/gaussian-splatting-3d.md; satellite and weather data in references/insurance-risk-assessment.md.
  • Boundary markers: No explicit sanitization or instructions to ignore embedded commands within the processed data streams were detected.
  • Capability inventory: The skill possesses extensive capabilities including file system writes (shutil.copy, open().write()), network operations (requests.post), and shell command execution (subprocess.run).
  • Sanitization: Standard computer vision and math libraries are utilized for data transformation, but there is no evidence of specific sanitization for file paths or parameters passed to shell commands.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 06:08 PM
Security Audit — agent-trust-hub — drone-inspection-specialist