monitor-security

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The _run_skill function in threat_intel.py executes sibling skill scripts using arguments parsed from external untrusted sources. Specifically, CVE IDs and descriptions obtained from RSS feeds and social media platforms are passed directly to subprocess calls. The author explicitly acknowledges in WALKTHROUGH.md that malicious input from these feeds could contain shell metacharacters to trigger command injection.
  • [COMMAND_EXECUTION]: The orchestrator frequently uses subprocess.run and os.system equivalents to invoke a wide range of security tools and sibling skills. Multiple probes in probes/tier0_deterministic.py, probes/tier2_docker_selfhack.py, and probes/tier3_cascade.py contain instances of shell command execution, including building Docker images and running isolated security audits.
  • [EXTERNAL_DOWNLOADS]: The skill integrates with consume-feed and social-bridge to download security advisories and threat intelligence from the internet. It also relies on external registries to install security scanning tools like semgrep, trivy, and pip-audit during the execution of its Docker-based scanning environment.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection. It ingests untrusted data from the web (RSS, social media) which is then used to drive the logic of security research tools like dogpile. A crafted malicious advisory could influence the agent's behavior or provide malicious arguments to downstream tools.
  • [CREDENTIALS_UNSAFE]: The system is designed to detect hardcoded secrets and includes specific rules and probes (gitleaks, secrets-detection) to search for credentials. This indicates the skill operates with high-privilege access to the project's source code and configuration files where it handles sensitive data related to the system's security posture.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — monitor-security