html-skills-listen

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell scripts and a Node.js server to manage the communication lifecycle.
  • Evidence: SKILL.md runs bash scripts/listen.sh and uses the Monitor tool to tail log files.
  • Evidence: scripts/listen.sh spawns server.js using nohup node.
  • [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface by ingesting untrusted data from a local HTTP server and feeding it into the agent's context.
  • Ingestion points: The server.js script listens for HTTP POST requests on 127.0.0.1 and outputs the payload to a log file.
  • Boundary markers: No delimiters or protective instructions are used when the Monitor tool injects the log content into the session.
  • Capability inventory: The agent has access to shell commands and file writing, which could be targeted by malicious payloads delivered through this channel.
  • Sanitization: server.js performs minimal metadata validation but forwards the raw request body to the agent.
  • [DATA_EXFILTRATION]: The local server in server.js uses an overly permissive CORS policy (Access-Control-Allow-Origin: '*'), which allows any website visited by the user to interact with the local listener and potentially influence the agent session.
  • [SAFE]: The script uses predictable file paths in /tmp (e.g., /tmp/html-skills-$SID.pid) for process and log management. In multi-user environments, this can lead to local information disclosure or symbolic link attacks, although it is common for development tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 04:18 AM
Security Audit — agent-trust-hub — html-skills-listen