protheus-reports

Warn

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The Excel generation templates in both 'SKILL.md' and 'references/treport-examples.md' utilize the 'ShellExecute' function with the 'Open' verb to automatically launch the generated file or its parent directory. The target path is sourced from user-defined parameters ('MV_PARxx'), which allows for the execution of arbitrary files or opening of malicious directories if the parameter input is not strictly validated.
  • [DATA_EXFILTRATION]: The skill's SQL query templates consistently demonstrate a pattern of concatenating user-provided parameters ('MV_PAR01', 'MV_PAR02', etc.) directly into query strings. This pattern is highly susceptible to SQL injection, which could be used by an attacker to bypass intended report filters and access or exfiltrate sensitive data from the underlying database tables such as 'SB2' (Products) or 'SE2' (Accounts Payable).
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a data ingestion surface by reading records from the Protheus database and exporting them to Excel or PDF. While the capability is standard for report generation, the lack of sanitization mentioned in the SQL construction findings increases the risk that malicious data within the database could influence the agent's behavior during the report generation process.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 2, 2026, 05:14 PM