brain-taxonomist
Warn
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing shell commands via the
gbrainCLI tool to fetch taxonomy data and schema packs. - [COMMAND_EXECUTION]: The instructions explicitly direct the agent to pass user-supplied arguments (e.g.,
--source <id>) directly into shell commands. This pattern is vulnerable to command injection if the agent environment does not properly escape or validate the input before executing the subprocess.
Audit Metadata