agent-inbox
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
verify_fixfunction indispatch_agent.pyanddispatcher_agent.pyexecutes atest_commandstring directly from the message metadata usingsubprocess.run(shell=True). Since the dispatcher daemon automatically processes pending messages from the filesystem, an attacker or a compromised agent can trigger arbitrary command execution by writing a malicious message file to the inbox directory. - [REMOTE_CODE_EXECUTION]: The
spawn_agentfunction indispatch_agent.pyanddispatcher_agent.pyinitiates headless AI agents using CLI tools likeclaude,pi, orcodex. These agents are passed a prompt constructed from untrusted message content, which can be used to trick the headless agent into executing malicious code within the target project's environment. - [DATA_EXFILTRATION]: The
triage.pymodule implements a webhook system that sends message data and status updates to user-defined external URLs. While the module includes basic protections against private IP ranges and enforces HTTPS by default, it provides a functional channel for data to be sent out of the environment. - [PROMPT_INJECTION]: The
build_promptfunction (found indispatch_core.pyanddispatcher_agent.py) lacks sufficient boundary markers or 'ignore' instructions when interpolating themessagecontent from the inbox. This exposes the headless agents to indirect prompt injection, where a malicious message can override the agent's instructions. - Ingestion points: Message files located in
~/.agent-inbox/pending/(processed indispatch_agent.py). - Boundary markers: Limited to markdown headers (e.g.,
## Description); lacks explicit safety delimiters or instructions to ignore embedded commands. - Capability inventory: Subprocess spawning (
subprocess.Popen), arbitrary shell execution (subprocess.run), and network access via webhooks (urllib.request). - Sanitization: No sanitization or validation of the message content or the
test_commandbefore use.
Recommendations
- AI detected serious security threats
Audit Metadata