skills/dfinity/icskills/canhelp/Gen Agent Trust Hub

canhelp

Warn

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts/resolve-canister-id.sh file contains a Python execution pattern (python3 -c "...") that directly interpolates the $INPUT shell variable into a Python string literal. Because this interpolation occurs before the Python interpreter evaluates the code, a user-provided canister name containing quotes or parentheses (e.g., "); import os; os.system("id") #) can break out of the intended string and execute arbitrary Python commands in the host environment.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute local bash scripts (resolve-canister-id.sh and fetch-candid.sh) using user-provided arguments. While the skill correctly uses quotes in most places, the aforementioned interpolation flaw makes this execution path unsafe.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from the official Internet Computer API at ic-api.internetcomputer.org to resolve canister names. It also uses the icp CLI tool to download Candid interface files from the network. These operations are consistent with the skill's stated purpose and target vendor-controlled infrastructure.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize Candid interface definitions (.did files) retrieved from remote canisters. This presents an indirect injection surface where a canister owner could embed malicious instructions within documentation comments or method names to manipulate the agent's summary output.
  • Ingestion points: Canister metadata retrieved via the icp CLI and results from the IC Dashboard API.
  • Boundary markers: None present; the agent is instructed to read the raw file and summarize it.
  • Capability inventory: File reading (Read), shell execution (Bash), and pattern matching (Grep, Glob).
  • Sanitization: Input is URL-encoded for the API query, but the subsequent error handling logic is vulnerable to the execution flaw noted above.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 16, 2026, 02:49 PM
Security Audit — agent-trust-hub — canhelp