command-resource-profiler
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/profile_command.pyexecutes arbitrary user-supplied commands viasubprocess.Popen. This is the intended core functionality of the skill, used to monitor and report process-tree resource usage. - [COMMAND_EXECUTION]: The profiler provides a
--shellflag that enables execution through the system shell. The script usesshlex.joinandsubprocess.list2cmdlineto format arguments, which helps mitigate some risks associated with shell execution, although shell mode remains a higher-risk capability than direct execution. - [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection as it ingests and executes commands provided to the profiler. 1. Ingestion points: Target command and arguments provided via the CLI to
profile_command.py. 2. Boundary markers: The script documentation and implementation encourage the use of the--separator to isolate the target command from profiler options. 3. Capability inventory: The skill has the capability to execute arbitrary commands and write JSON/CSV reports to local paths. 4. Sanitization: The script treats the command as a list of arguments and uses standard Python subprocess modules for execution, providing basic isolation from shell-based injection unless the shell mode is explicitly requested.
Audit Metadata