discover-talent

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection by processing external data from the TMDB API.
  • Ingestion points: Actor biographies and movie metadata fetched from api.themoviedb.org in discover_talent/tmdb_client.py.
  • Boundary markers: No explicit delimiters are used to wrap external content when it is presented to the agent or console.
  • Capability inventory: The skill possesses network access and shell command execution capabilities via run.sh.
  • Sanitization: Actor biographies are truncated to 500 characters, which offers limited mitigation.
  • [REMOTE_CODE_EXECUTION]: The run.sh script includes a suggested command for installing the 'uv' package manager via a piped shell script.
  • Evidence: The script echoes the command 'curl -LsSf https://astral.sh/uv/install.sh | sh' if uv is missing.
  • Context: Astral is a well-known and reputable service in the Python ecosystem, and this reference is for manual user installation.
  • [EXTERNAL_DOWNLOADS]: The skill manages several third-party Python dependencies.
  • Evidence: Dependencies are listed in pyproject.toml and managed via the uv tool.
  • Context: All referenced packages (httpx, rich, typer, etc.) are standard, well-known libraries from the official Python Package Index (PyPI).
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — discover-talent