export-oscal
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript is vulnerable to command injection in thevalidatesubcommand. The user-provided file path is directly interpolated into a Python command string (python3 -c "path = '$FILE' ...") without escaping single quotes. An attacker who can influence the filename (e.g., by creating a file with a name containing a single quote and Python code) can execute arbitrary Python commands when the validation logic is triggered. - [COMMAND_EXECUTION]: The
exportsubcommand inrun.shfollows an unsafe pattern of interpolating shell variables into Python execution strings (python3 -c "framework = '$FRAMEWORK' ..."). While currently mitigated by a whitelist check, this pattern is inherently insecure and represents a risk if the validation logic is ever modified or bypassed. - [REMOTE_CODE_EXECUTION]: The skill dynamically constructs a path to an external script located in a sibling directory (
../memory/run.sh) and executes it using thesubprocessmodule. This creates a dependency on an external script whose integrity cannot be verified by the skill itself. - [DATA_EXFILTRATION]: The skill accesses and exports sensitive compliance evidence from database collections including
sparta_controls,sparta_qra, andlessons. While this is the stated purpose, the access to organizational security data represents a high-value target for exfiltration if the agent is misdirected.
Recommendations
- AI detected serious security threats
Audit Metadata