monitor-misuse

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/apply.py performs direct write operations to Python files (_misuse_guard.py) to update the COLLECTION_CORRECTIONS dictionary. This capability allows the skill to modify the logic of other skills at runtime. Because the content written to these files is derived from untrusted events and LLM output, this presents a high risk of code injection and system integrity compromise.
  • [CREDENTIALS_UNSAFE]: The file scripts/analyze.py contains a hardcoded API key sk-dev-proxy-123 for the local SCILLM proxy service.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes untrusted data to generate code changes.
  • Ingestion points: scripts/analyze.py fetches sent_value data from the misuse_events collection which originates from external API callers.
  • Boundary markers: None; external data is directly interpolated into the LLM prompt using f-strings.
  • Capability inventory: The skill has filesystem write access to specific paths in the user's workspace via scripts/apply.py.
  • Sanitization: There is no validation or escaping of the sent_value data before prompt injection, nor is the LLM output validated before being written to Python files.
  • [DATA_EXFILTRATION]: scripts/analyze.py transmits event data, which may contain sensitive parameters or user inputs from the sent_value field, to a local LLM proxy at http://localhost:4001.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — monitor-misuse