persona-dream
Fail
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation (SKILL.md) specifies a command
curl -s http://127.0.0.1:8018/health | python3which pipes network output directly to an interpreter. This pattern is inherently unsafe and provides a mechanism for local code execution through network responses. - [COMMAND_EXECUTION]: The skill relies on
run.shfor orchestration, which executes shell commands that can be influenced by untrusted data sources the agent interacts with, such as search results and provider returns. - [PROMPT_INJECTION]: The skill exhibits a significant attack surface for indirect prompt injection (Category 8). It ingests untrusted data from Brave Search and Kling video returns. It lacks explicit boundary markers or 'ignore embedded instructions' directives when processing this data, potentially allowing external content to influence the agent's behavior while it possesses shell execution capabilities. Mandatory Evidence Chain: 1. Ingestion points: brave-search and Kling provider returns (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution via run.sh (SKILL.md). 4. Sanitization: Not explicitly implemented in processing logic.
- [CREDENTIALS_UNSAFE]: SKILL.md contains an example Bearer token starting with the sensitive prefix 'sk-dev-proxy-123'. While intended as a placeholder, hardcoding patterns that resemble active API keys in documentation or scripts is a risky practice.
- [DYNAMIC_EXECUTION]: SKILL.md includes a code snippet that generates JWT tokens by executing dynamic Python code via
python3 -c, a technique that assembles and executes code at runtime.
Recommendations
- HIGH: Downloads and executes remote code from: http://127.0.0.1:8018/health - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata