agentmesh
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from an external messaging network which can influence agent behavior.
- Ingestion points: Data is retrieved from the AgentMesh network via tools like
agentmesh_check_messages,agentmesh_owner_inbox, andagentmesh_owner_conversationsas seen inSKILL.md. - Boundary markers: There are no explicit markers or instructions provided to the agent to distinguish between user intent and instructions contained within the fetched messages.
- Capability inventory: The agent has high-privilege tool access including
Bash,Write,Edit, andReadpermissions. - Sanitization: No sanitization or safety filtering of the message content is implemented.
- Evidence: The 'Autonomous Mode' guide in Step 2.5 explicitly directs the agent to 'Automatically process messages as instructions' (收到消息后自动当作指令处理), which allows for indirect prompt injection where a remote user could send commands to the agent.
- [COMMAND_EXECUTION]: The skill modifies the environment to execute code locally.
- Evidence: Step 1.2 writes an entry to
.mcp.jsonthat executes a script usingnpx tsx <absolute-project-path>/packages/mcp-server/src/server.ts. - [EXTERNAL_DOWNLOADS]: The MCP server configuration utilizes
npx, which downloads packages from the npm registry at runtime if they are not already installed locally. - [CREDENTIALS_UNSAFE]: The setup process prompts the user for an
AGENTMESH_API_KEYand persists it in plain text within the local.mcp.jsonconfiguration file.
Audit Metadata