html-skills-listen
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local shell scripts and a Node.js server to manage the communication lifecycle.
- Evidence:
SKILL.mdrunsbash scripts/listen.shand uses theMonitortool to tail log files. - Evidence:
scripts/listen.shspawnsserver.jsusingnohup node. - [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface by ingesting untrusted data from a local HTTP server and feeding it into the agent's context.
- Ingestion points: The
server.jsscript listens for HTTP POST requests on127.0.0.1and outputs the payload to a log file. - Boundary markers: No delimiters or protective instructions are used when the
Monitortool injects the log content into the session. - Capability inventory: The agent has access to shell commands and file writing, which could be targeted by malicious payloads delivered through this channel.
- Sanitization:
server.jsperforms minimal metadata validation but forwards the raw request body to the agent. - [DATA_EXFILTRATION]: The local server in
server.jsuses an overly permissive CORS policy (Access-Control-Allow-Origin: '*'), which allows any website visited by the user to interact with the local listener and potentially influence the agent session. - [SAFE]: The script uses predictable file paths in
/tmp(e.g.,/tmp/html-skills-$SID.pid) for process and log management. In multi-user environments, this can lead to local information disclosure or symbolic link attacks, although it is common for development tools.
Audit Metadata