agent-inbox

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The verify_fix function in dispatch_agent.py and dispatcher_agent.py executes a test_command string directly from the message metadata using subprocess.run(shell=True). Since the dispatcher daemon automatically processes pending messages from the filesystem, an attacker or a compromised agent can trigger arbitrary command execution by writing a malicious message file to the inbox directory.
  • [REMOTE_CODE_EXECUTION]: The spawn_agent function in dispatch_agent.py and dispatcher_agent.py initiates headless AI agents using CLI tools like claude, pi, or codex. These agents are passed a prompt constructed from untrusted message content, which can be used to trick the headless agent into executing malicious code within the target project's environment.
  • [DATA_EXFILTRATION]: The triage.py module implements a webhook system that sends message data and status updates to user-defined external URLs. While the module includes basic protections against private IP ranges and enforces HTTPS by default, it provides a functional channel for data to be sent out of the environment.
  • [PROMPT_INJECTION]: The build_prompt function (found in dispatch_core.py and dispatcher_agent.py) lacks sufficient boundary markers or 'ignore' instructions when interpolating the message content from the inbox. This exposes the headless agents to indirect prompt injection, where a malicious message can override the agent's instructions.
  • Ingestion points: Message files located in ~/.agent-inbox/pending/ (processed in dispatch_agent.py).
  • Boundary markers: Limited to markdown headers (e.g., ## Description); lacks explicit safety delimiters or instructions to ignore embedded commands.
  • Capability inventory: Subprocess spawning (subprocess.Popen), arbitrary shell execution (subprocess.run), and network access via webhooks (urllib.request).
  • Sanitization: No sanitization or validation of the message content or the test_command before use.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — agent-inbox