best-practices-agent
Fail
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill includes a Python code snippet with a hardcoded bearer token pattern 'sk-dev-proxy-123'. While presented as a placeholder for a local development proxy, it matches high-entropy credential patterns.
- Evidence:
headers={"Authorization": "Bearer sk-dev-proxy-123"}in SKILL.md. - [COMMAND_EXECUTION]: The instructions direct the agent to execute system management commands to control local daemon services.
- Evidence:
systemctl --user start embry-memoryin SKILL.md. - [PROMPT_INJECTION]: The skill establishes an indirect prompt injection surface (Category 8) by defining workflows where an agent processes untrusted data and executes automated repair orchestration.
- Ingestion points: 'WebGPT responses', 'source text', and 'manifests' (SKILL.md).
- Boundary markers: No requirement for data delimiters or 'ignore' instructions for embedded content was identified.
- Capability inventory: The agent is authorized to perform local network operations via
httpx, execute system commands, and run automated repair logic. - Sanitization: The framework lacks specific rules for sanitizing or validating external content before it influences automated decisions or repair actions.
Recommendations
- AI detected serious security threats
Audit Metadata