flox-environments
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to interact with and activate environments defined in
.flox/env/manifest.toml. This creates an attack surface where a malicious repository could include harmful shell commands in the manifest'son-activatehook orprofilesection. If the agent activates such an environment, the embedded commands will execute.\n - Ingestion points:
.flox/env/manifest.toml(SKILL.md)\n - Boundary markers: No specific delimiters or validation mechanisms are described to separate instructions from untrusted data within the manifest content.\n
- Capability inventory: The
flox activatecommand executes shell code;flox install,npm, anduvperform network operations and file system writes (SKILL.md).\n - Sanitization: The skill does not provide methods for sanitizing or validating the content of the TOML manifest before execution.\n- [EXTERNAL_DOWNLOADS]: The skill includes instructions for downloading software dependencies via standard package managers.\n
- Details: The documentation demonstrates the use of
npm install,uv pip install, andflox installto fetch tools and libraries from external registries (SKILL.md).\n- [COMMAND_EXECUTION]: The skill enables the execution of shell scripts and commands through Flox's environment activation process.\n - Details: User-defined shell scripts in the
[hook]and[profile]sections of the Flox manifest are executed when the environment is activated (SKILL.md).
Audit Metadata