export-oscal

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The run.sh script is vulnerable to command injection in the validate subcommand. The user-provided file path is directly interpolated into a Python command string (python3 -c "path = '$FILE' ...") without escaping single quotes. An attacker who can influence the filename (e.g., by creating a file with a name containing a single quote and Python code) can execute arbitrary Python commands when the validation logic is triggered.
  • [COMMAND_EXECUTION]: The export subcommand in run.sh follows an unsafe pattern of interpolating shell variables into Python execution strings (python3 -c "framework = '$FRAMEWORK' ..."). While currently mitigated by a whitelist check, this pattern is inherently insecure and represents a risk if the validation logic is ever modified or bypassed.
  • [REMOTE_CODE_EXECUTION]: The skill dynamically constructs a path to an external script located in a sibling directory (../memory/run.sh) and executes it using the subprocess module. This creates a dependency on an external script whose integrity cannot be verified by the skill itself.
  • [DATA_EXFILTRATION]: The skill accesses and exports sensitive compliance evidence from database collections including sparta_controls, sparta_qra, and lessons. While this is the stated purpose, the access to organizational security data represents a high-value target for exfiltration if the agent is misdirected.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — export-oscal