brain-taxonomist

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands via the gbrain CLI tool to fetch taxonomy data and schema packs.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to pass user-supplied arguments (e.g., --source <id>) directly into shell commands. This pattern is vulnerable to command injection if the agent environment does not properly escape or validate the input before executing the subprocess.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 04:43 AM
Security Audit — agent-trust-hub — brain-taxonomist