setup

Fail

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/humane_setup.py script utilizes subprocess.run(shell=True) to execute environment remediation commands.
  • [COMMAND_EXECUTION]: A command injection vulnerability exists in the handling of the token_base configuration setting. Values provided in a project's humane.json file are interpolated into shell commands (e.g., tokens setup-edit {base}) and executed without sanitization, enabling arbitrary code execution via malicious project files.
  • [DYNAMIC_EXECUTION]: The script performs dynamic module loading by modifying sys.path to import illustrate.py from a relative directory (../../brand-illustrate/scripts), which can be exploited for local code execution.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of third-party components, including the agent-browser package from npm and plugins from the jakubkrehel/skills GitHub repository.
  • [REMOTE_CODE_EXECUTION]: The inclusion of shell-executed commands derived from untrusted project-local configuration files allows for arbitrary code execution when interacting with a malicious repository.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 6, 2026, 01:18 PM