flox-environments

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses .flox/env/manifest.toml files which contain on-activate hooks and profile shell code snippets that are executed automatically whenever the environment is activated.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and act upon configuration from untrusted project-level files, creating a potential attack surface for indirect prompt injection.
  • Ingestion points: Reads and modifies .flox/env/manifest.toml, package.json, and requirements.txt (SKILL.md).
  • Boundary markers: None present; the agent treats the manifest content as trusted instructions for environment setup.
  • Capability inventory: Executes shell commands via hooks and profile definitions, performs package installations (flox install, npm install, pip install), and manages background services (SKILL.md).
  • Sanitization: No escaping or validation is specified for content interpolated from these files into shell contexts.
  • [COMMAND_EXECUTION]: The skill provides numerous patterns for executing shell commands and package managers (npm, pip, uv, cargo, gcc) within the environment lifecycle.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — flox-environments