ops-arango
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/dump.shis vulnerable to shell injection. It constructs a command string (DUMP_CMD) using variables likeARANGO_PASSandARANGO_DBwrapped in single quotes, and then executes this string inside a container viadocker exec "$CONTAINER" sh -lc "$DUMP_CMD". If these environment variables contain single quotes or other shell-terminating characters, an attacker could execute arbitrary commands within the context of the ArangoDB container. - [CREDENTIALS_UNSAFE]: The
scripts/dump.shscript includes logic to automatically extract theARANGO_ROOT_PASSWORDby runningdocker inspecton active containers. This is a privileged operation that retrieves sensitive secrets from the environment variables of other running processes. - [EXTERNAL_DOWNLOADS]: In
scripts/maintain.py, thecheck_embeddingsfunction sends document content (titles and descriptions) to an external endpoint defined byEMBEDDING_SERVICE_URL. This results in the exfiltration of database content to a remote service for processing. - [COMMAND_EXECUTION]: The skill uses
findcombined withrm -rfinscripts/dump.shto manage backup retention. While it uses-printf, the resulting paths are processed in awhile readloop without null-termination handling, which can lead to unexpected file deletion if directory names contain special characters.
Audit Metadata