scheduler

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The executor.py module utilizes subprocess.Popen and subprocess.run with shell=True to execute job commands. This facilitates arbitrary command execution based on the contents of the jobs.json registry file.\n- [REMOTE_CODE_EXECUTION]: The metrics server implemented in metrics_server.py binds to 0.0.0.0 by default and exposes a /jobs/{name}/run POST endpoint. This allows any user on the network to remotely trigger the execution of registered shell commands without authentication.\n- [DATA_EXFILTRATION]: The metrics server exposes job execution logs through the /jobs/{name}/logs endpoint. These logs are accessible to any network user without authentication and may contain sensitive data or credentials output by scheduled tasks.\n- [PROMPT_INJECTION]: The skill includes a load command that parses services.yaml files to register new tasks. This represents an indirect prompt injection surface where the agent could be manipulated into loading a malicious configuration file that registers unauthorized background commands.\n- [COMMAND_EXECUTION]: In executor.py, the skill attempts to execute a script at a relative path (../common/estimate_timeout.py) using subprocess.Popen. This behavior relies on specific directory structures and executes code outside the skill's own directory environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — scheduler