skills/ericrisco/rsc-harness/modal/Gen Agent Trust Hub

modal

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides recipes in its documentation that use subprocess.Popen with shell=True to launch server processes such as vLLM. While common for containerized workloads, this pattern is susceptible to command injection if parameters like model identifiers are derived from untrusted user inputs without sanitization.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines functions that ingest and process external data, creating a potential attack surface for indirect prompt injection.\n
  • Ingestion points: Function parameters such as the url argument in the fetch function (SKILL.md) and model configuration strings in the serve function (references/web-and-scaling.md).\n
  • Boundary markers: The provided code templates do not include specific delimiters or instructions to ignore embedded commands in external data.\n
  • Capability inventory: The skill facilitates network operations using the requests library, persistent file storage via modal.Volume, and shell command execution via subprocess.Popen.\n
  • Sanitization: The examples do not demonstrate input validation, escaping, or sanitization logic for data processed by the functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — modal