ops-nzbgeek
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its search functionality.
- Ingestion points: External data is fetched from the NZBGeek API in
ops_nzbgeek/search.py, specifically thetitle,description, andlinkfields of search results. - Boundary markers: No delimiters or instructions to ignore embedded commands were found when results are passed to the agent.
- Capability inventory: The skill can execute local bash scripts via
subprocess.run(inops_nzbgeek/interview_helper.py) and perform network operations to download content via SABnzbd (ops_nzbgeek/download.py). - Sanitization: There is no evidence of filtering or sanitization of the retrieved search result content before it is processed by the agent or displayed.
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto call therun.shscript of theinterviewskill located at~/.pi/skills/interview/run.sh. While this is intended for inter-skill communication, it represents a command execution pattern. - [CREDENTIALS_UNSAFE]: The skill reads and handles sensitive API keys for NZBGeek and SABnzbd. The sanity scripts (
sanity/nzbgeek-api.shandsanity/sabnzbd-api.sh) pass these keys as plaintext query parameters incurlcommands, which can expose them in process logs. Additionally, configuration is loaded from a hardcoded developer path (~/workspace/experiments/pi-mono/.env) in multiple modules.
Audit Metadata