scheduler
Warn
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
executor.pymodule utilizessubprocess.Popenandsubprocess.runwithshell=Trueto execute job commands. This facilitates arbitrary command execution based on the contents of thejobs.jsonregistry file.\n- [REMOTE_CODE_EXECUTION]: The metrics server implemented inmetrics_server.pybinds to0.0.0.0by default and exposes a/jobs/{name}/runPOST endpoint. This allows any user on the network to remotely trigger the execution of registered shell commands without authentication.\n- [DATA_EXFILTRATION]: The metrics server exposes job execution logs through the/jobs/{name}/logsendpoint. These logs are accessible to any network user without authentication and may contain sensitive data or credentials output by scheduled tasks.\n- [PROMPT_INJECTION]: The skill includes aloadcommand that parsesservices.yamlfiles to register new tasks. This represents an indirect prompt injection surface where the agent could be manipulated into loading a malicious configuration file that registers unauthorized background commands.\n- [COMMAND_EXECUTION]: Inexecutor.py, the skill attempts to execute a script at a relative path (../common/estimate_timeout.py) usingsubprocess.Popen. This behavior relies on specific directory structures and executes code outside the skill's own directory environment.
Audit Metadata