dx-code-analyzer-run

Warn

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts/describe-rule.js script is vulnerable to shell command injection. It uses child_process.execSync to execute a command that interpolates user-provided rule names into a shell string without sanitization. An attacker can execute arbitrary commands by providing a rule name containing shell metacharacters (e.g., ;, &, |).
  • [COMMAND_EXECUTION]: The scripts/apply-fixes.js script performs in-place file modifications based on paths specified in an input JSON results file. The script does not validate that these file paths are within the project workspace, creating a risk of unauthorized file writes or overwrites if the agent processes a malicious results file.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from code scans that could be influenced by malicious source files, creating an attack surface for indirect injection.
  • Ingestion points: Scan results in JSON format (code-analyzer-results-*.json) processed by utility scripts such as scripts/apply-fixes.js and scripts/query-results.js.
  • Boundary markers: None. The scripts do not use specific delimiters or instructions to ignore malicious content within the results.
  • Capability inventory: The skill uses child_process for shell execution and fs for reading/writing files, providing significant system access.
  • Sanitization: Insufficient. While scripts/list-rules.js includes a token validator, scripts/describe-rule.js and scripts/apply-fixes.js do not sanitize their inputs or validate file paths.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 3, 2026, 06:32 PM
Security Audit — agent-trust-hub — dx-code-analyzer-run