monitor-misuse
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/apply.pyperforms direct write operations to Python files (_misuse_guard.py) to update theCOLLECTION_CORRECTIONSdictionary. This capability allows the skill to modify the logic of other skills at runtime. Because the content written to these files is derived from untrusted events and LLM output, this presents a high risk of code injection and system integrity compromise. - [CREDENTIALS_UNSAFE]: The file
scripts/analyze.pycontains a hardcoded API keysk-dev-proxy-123for the localSCILLMproxy service. - [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes untrusted data to generate code changes.
- Ingestion points:
scripts/analyze.pyfetchessent_valuedata from themisuse_eventscollection which originates from external API callers. - Boundary markers: None; external data is directly interpolated into the LLM prompt using f-strings.
- Capability inventory: The skill has filesystem write access to specific paths in the user's workspace via
scripts/apply.py. - Sanitization: There is no validation or escaping of the
sent_valuedata before prompt injection, nor is the LLM output validated before being written to Python files. - [DATA_EXFILTRATION]:
scripts/analyze.pytransmits event data, which may contain sensitive parameters or user inputs from thesent_valuefield, to a local LLM proxy athttp://localhost:4001.
Recommendations
- AI detected serious security threats
Audit Metadata