agents-registry
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
agents_registry/cli.pyscript usessubprocess.runwithin the_sync_to_memoryfunction to execute a memory management tool. While the command and arguments are constructed as a list, which helps prevent shell injection, it does invoke external processes based on parsed metadata. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface in
agents_registry/cli.py. - Ingestion points: Reads
AGENTS.mdfiles from.pi/agents/*/directories. - Boundary markers: The script uses
yaml.safe_loadto parse frontmatter, which is a good practice, but the extracted strings (name, scope, provides, composes, etc.) are later interpolated into a text document for memory storage without further sanitization. - Capability inventory: Uses
subprocess.runto sync the processed metadata to a persistent memory store (ArangoDB). - Sanitization: Uses
yaml.safe_loadfor parsing, but does not sanitize the resulting strings before they are formatted into thedocstring used for memory ingestion. This could allow maliciously crafted metadata in anAGENTS.mdfile to influence the semantic search results or agent routing logic.
Audit Metadata