skills/flora131/atomic/tool-design/Gen Agent Trust Hub

tool-design

Warn

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill and its references (references/architectural_reduction.md) explicitly promote the "File System Agent Pattern," which involves providing the agent with a tool to execute arbitrary bash commands. This capability allows the agent to run any shell utility (such as grep, cat, and find) on the host system or within a sandbox environment.
  • [REMOTE_CODE_EXECUTION]: By providing a generic execute_command tool for "arbitrary bash" execution, the skill establishes a high-risk attack surface. If an agent using this architecture processes untrusted input, an attacker could potentially inject malicious shell commands that the agent then executes, leading to full remote code execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 5, 2026, 04:38 PM