canhelp
Warn
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The
scripts/resolve-canister-id.shfile contains a Python execution pattern (python3 -c "...") that directly interpolates the$INPUTshell variable into a Python string literal. Because this interpolation occurs before the Python interpreter evaluates the code, a user-provided canister name containing quotes or parentheses (e.g.,"); import os; os.system("id") #) can break out of the intended string and execute arbitrary Python commands in the host environment. - [COMMAND_EXECUTION]: The skill instructions direct the agent to execute local bash scripts (
resolve-canister-id.shandfetch-candid.sh) using user-provided arguments. While the skill correctly uses quotes in most places, the aforementioned interpolation flaw makes this execution path unsafe. - [EXTERNAL_DOWNLOADS]: The skill fetches data from the official Internet Computer API at
ic-api.internetcomputer.orgto resolve canister names. It also uses theicpCLI tool to download Candid interface files from the network. These operations are consistent with the skill's stated purpose and target vendor-controlled infrastructure. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize Candid interface definitions (
.didfiles) retrieved from remote canisters. This presents an indirect injection surface where a canister owner could embed malicious instructions within documentation comments or method names to manipulate the agent's summary output. - Ingestion points: Canister metadata retrieved via the
icpCLI and results from the IC Dashboard API. - Boundary markers: None present; the agent is instructed to read the raw file and summarize it.
- Capability inventory: File reading (
Read), shell execution (Bash), and pattern matching (Grep,Glob). - Sanitization: Input is URL-encoded for the API query, but the subsequent error handling logic is vulnerable to the execution flaw noted above.
Audit Metadata