agents-registry

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The agents_registry/cli.py script uses subprocess.run within the _sync_to_memory function to execute a memory management tool. While the command and arguments are constructed as a list, which helps prevent shell injection, it does invoke external processes based on parsed metadata.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface in agents_registry/cli.py.
  • Ingestion points: Reads AGENTS.md files from .pi/agents/*/ directories.
  • Boundary markers: The script uses yaml.safe_load to parse frontmatter, which is a good practice, but the extracted strings (name, scope, provides, composes, etc.) are later interpolated into a text document for memory storage without further sanitization.
  • Capability inventory: Uses subprocess.run to sync the processed metadata to a persistent memory store (ArangoDB).
  • Sanitization: Uses yaml.safe_load for parsing, but does not sanitize the resulting strings before they are formatted into the doc string used for memory ingestion. This could allow maliciously crafted metadata in an AGENTS.md file to influence the semantic search results or agent routing logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — agents-registry