dx-code-analyzer-run
Warn
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
scripts/describe-rule.jsscript is vulnerable to shell command injection. It useschild_process.execSyncto execute a command that interpolates user-provided rule names into a shell string without sanitization. An attacker can execute arbitrary commands by providing a rule name containing shell metacharacters (e.g.,;,&,|). - [COMMAND_EXECUTION]: The
scripts/apply-fixes.jsscript performs in-place file modifications based on paths specified in an input JSON results file. The script does not validate that these file paths are within the project workspace, creating a risk of unauthorized file writes or overwrites if the agent processes a malicious results file. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from code scans that could be influenced by malicious source files, creating an attack surface for indirect injection.
- Ingestion points: Scan results in JSON format (
code-analyzer-results-*.json) processed by utility scripts such asscripts/apply-fixes.jsandscripts/query-results.js. - Boundary markers: None. The scripts do not use specific delimiters or instructions to ignore malicious content within the results.
- Capability inventory: The skill uses
child_processfor shell execution andfsfor reading/writing files, providing significant system access. - Sanitization: Insufficient. While
scripts/list-rules.jsincludes a token validator,scripts/describe-rule.jsandscripts/apply-fixes.jsdo not sanitize their inputs or validate file paths.
Audit Metadata