ops-nzbgeek

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its search functionality.
  • Ingestion points: External data is fetched from the NZBGeek API in ops_nzbgeek/search.py, specifically the title, description, and link fields of search results.
  • Boundary markers: No delimiters or instructions to ignore embedded commands were found when results are passed to the agent.
  • Capability inventory: The skill can execute local bash scripts via subprocess.run (in ops_nzbgeek/interview_helper.py) and perform network operations to download content via SABnzbd (ops_nzbgeek/download.py).
  • Sanitization: There is no evidence of filtering or sanitization of the retrieved search result content before it is processed by the agent or displayed.
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to call the run.sh script of the interview skill located at ~/.pi/skills/interview/run.sh. While this is intended for inter-skill communication, it represents a command execution pattern.
  • [CREDENTIALS_UNSAFE]: The skill reads and handles sensitive API keys for NZBGeek and SABnzbd. The sanity scripts (sanity/nzbgeek-api.sh and sanity/sabnzbd-api.sh) pass these keys as plaintext query parameters in curl commands, which can expose them in process logs. Additionally, configuration is loaded from a hardcoded developer path (~/workspace/experiments/pi-mono/.env) in multiple modules.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — ops-nzbgeek