monitor-security
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
_run_skillfunction inthreat_intel.pyexecutes sibling skill scripts using arguments parsed from external untrusted sources. Specifically, CVE IDs and descriptions obtained from RSS feeds and social media platforms are passed directly to subprocess calls. The author explicitly acknowledges inWALKTHROUGH.mdthat malicious input from these feeds could contain shell metacharacters to trigger command injection. - [COMMAND_EXECUTION]: The orchestrator frequently uses
subprocess.runandos.systemequivalents to invoke a wide range of security tools and sibling skills. Multiple probes inprobes/tier0_deterministic.py,probes/tier2_docker_selfhack.py, andprobes/tier3_cascade.pycontain instances of shell command execution, including building Docker images and running isolated security audits. - [EXTERNAL_DOWNLOADS]: The skill integrates with
consume-feedandsocial-bridgeto download security advisories and threat intelligence from the internet. It also relies on external registries to install security scanning tools likesemgrep,trivy, andpip-auditduring the execution of its Docker-based scanning environment. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It ingests untrusted data from the web (RSS, social media) which is then used to drive the logic of security research tools like
dogpile. A crafted malicious advisory could influence the agent's behavior or provide malicious arguments to downstream tools. - [CREDENTIALS_UNSAFE]: The system is designed to detect hardcoded secrets and includes specific rules and probes (
gitleaks,secrets-detection) to search for credentials. This indicates the skill operates with high-privilege access to the project's source code and configuration files where it handles sensitive data related to the system's security posture.
Recommendations
- AI detected serious security threats
Audit Metadata