setup
Fail
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/humane_setup.pyscript utilizessubprocess.run(shell=True)to execute environment remediation commands. - [COMMAND_EXECUTION]: A command injection vulnerability exists in the handling of the
token_baseconfiguration setting. Values provided in a project'shumane.jsonfile are interpolated into shell commands (e.g.,tokens setup-edit {base}) and executed without sanitization, enabling arbitrary code execution via malicious project files. - [DYNAMIC_EXECUTION]: The script performs dynamic module loading by modifying
sys.pathto importillustrate.pyfrom a relative directory (../../brand-illustrate/scripts), which can be exploited for local code execution. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of third-party components, including the
agent-browserpackage fromnpmand plugins from thejakubkrehel/skillsGitHub repository. - [REMOTE_CODE_EXECUTION]: The inclusion of shell-executed commands derived from untrusted project-local configuration files allows for arbitrary code execution when interacting with a malicious repository.
Recommendations
- AI detected serious security threats
Audit Metadata