ops-arango

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/dump.sh is vulnerable to shell injection. It constructs a command string (DUMP_CMD) using variables like ARANGO_PASS and ARANGO_DB wrapped in single quotes, and then executes this string inside a container via docker exec "$CONTAINER" sh -lc "$DUMP_CMD". If these environment variables contain single quotes or other shell-terminating characters, an attacker could execute arbitrary commands within the context of the ArangoDB container.
  • [CREDENTIALS_UNSAFE]: The scripts/dump.sh script includes logic to automatically extract the ARANGO_ROOT_PASSWORD by running docker inspect on active containers. This is a privileged operation that retrieves sensitive secrets from the environment variables of other running processes.
  • [EXTERNAL_DOWNLOADS]: In scripts/maintain.py, the check_embeddings function sends document content (titles and descriptions) to an external endpoint defined by EMBEDDING_SERVICE_URL. This results in the exfiltration of database content to a remote service for processing.
  • [COMMAND_EXECUTION]: The skill uses find combined with rm -rf in scripts/dump.sh to manage backup retention. While it uses -printf, the resulting paths are processed in a while read loop without null-termination handling, which can lead to unexpected file deletion if directory names contain special characters.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ops-arango