flox-environments

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to interact with and activate environments defined in .flox/env/manifest.toml. This creates an attack surface where a malicious repository could include harmful shell commands in the manifest's on-activate hook or profile section. If the agent activates such an environment, the embedded commands will execute.\n
  • Ingestion points: .flox/env/manifest.toml (SKILL.md)\n
  • Boundary markers: No specific delimiters or validation mechanisms are described to separate instructions from untrusted data within the manifest content.\n
  • Capability inventory: The flox activate command executes shell code; flox install, npm, and uv perform network operations and file system writes (SKILL.md).\n
  • Sanitization: The skill does not provide methods for sanitizing or validating the content of the TOML manifest before execution.\n- [EXTERNAL_DOWNLOADS]: The skill includes instructions for downloading software dependencies via standard package managers.\n
  • Details: The documentation demonstrates the use of npm install, uv pip install, and flox install to fetch tools and libraries from external registries (SKILL.md).\n- [COMMAND_EXECUTION]: The skill enables the execution of shell scripts and commands through Flox's environment activation process.\n
  • Details: User-defined shell scripts in the [hook] and [profile] sections of the Flox manifest are executed when the environment is activated (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — flox-environments