ops-f36-plant
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The
buttons.yamlmanifest defines several commands that use the$(xclip -o)subshell expansion to retrieve data from the clipboard. This data is directly interpolated into shell commands (e.g.,pi f36 test torque --part-id $(xclip -o)). If the clipboard contains shell metacharacters such as semicolons, pipes, or backticks, it could trigger unauthorized command execution when a Stream Deck button is activated. - [DATA_EXPOSURE_AND_EXFILTRATION]: The
run.shscript sources the project's.envfile (source "$PROJECT_ROOT/.env"). This action exposes all environment variables, which may include sensitive API keys or credentials, to the skill's environment. - [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the skill's context via the system clipboard (
xclip -oinrun.shandbuttons.yaml) and the barcode scanner (zbarcaminrun.sh). - Boundary markers: No delimiters or "ignore instructions" prompts are used when processing the
PART_IDor barcode data. - Capability inventory: The skill calls several other powerful skills, including
agent-inbox(sending messages),episodic-archiver(permanent storage), andbatch-quality(approving/rejecting material), and can capture images usingfswebcam. - Sanitization: The skill lacks validation or escaping logic for the ingested data before passing it to sub-skills or logging it.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The
run.shscript relies on external system utilities such asfswebcam,zbarcam, andxclip, and instructs the user to install them viaapt. This introduces a dependency on external software maintainers and system-level tools that operate outside the skill's immediate control.
Audit Metadata