command-resource-profiler

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/profile_command.py executes arbitrary user-supplied commands via subprocess.Popen. This is the intended core functionality of the skill, used to monitor and report process-tree resource usage.
  • [COMMAND_EXECUTION]: The profiler provides a --shell flag that enables execution through the system shell. The script uses shlex.join and subprocess.list2cmdline to format arguments, which helps mitigate some risks associated with shell execution, although shell mode remains a higher-risk capability than direct execution.
  • [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it ingests and executes commands provided to the profiler. 1. Ingestion points: Target command and arguments provided via the CLI to profile_command.py. 2. Boundary markers: The script documentation and implementation encourage the use of the -- separator to isolate the target command from profiler options. 3. Capability inventory: The skill has the capability to execute arbitrary commands and write JSON/CSV reports to local paths. 4. Sanitization: The script treats the command as a list of arguments and uses standard Python subprocess modules for execution, providing basic isolation from shell-based injection unless the shell mode is explicitly requested.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:43 PM
Security Audit — agent-trust-hub — command-resource-profiler