flox-environments
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill uses
.flox/env/manifest.tomlfiles which containon-activatehooks andprofileshell code snippets that are executed automatically whenever the environment is activated. - [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and act upon configuration from untrusted project-level files, creating a potential attack surface for indirect prompt injection.
- Ingestion points: Reads and modifies
.flox/env/manifest.toml,package.json, andrequirements.txt(SKILL.md). - Boundary markers: None present; the agent treats the manifest content as trusted instructions for environment setup.
- Capability inventory: Executes shell commands via hooks and profile definitions, performs package installations (
flox install,npm install,pip install), and manages background services (SKILL.md). - Sanitization: No escaping or validation is specified for content interpolated from these files into shell contexts.
- [COMMAND_EXECUTION]: The skill provides numerous patterns for executing shell commands and package managers (
npm,pip,uv,cargo,gcc) within the environment lifecycle.
Audit Metadata