fix-review
Fail
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions in
commands/fix-review.mdandreferences/report-parsing.mdfor handling Google Drive URLs are vulnerable to command injection. The recommended bash snippets, such asFILE_ID=$(echo "<url>" | ...), do not specify proper escaping for the<url>placeholder. An attacker could provide a crafted URL containing shell metacharacters (e.g., backticks, semi-colons, or command substitutions) to execute arbitrary shell commands within the agent's environment. - [EXTERNAL_DOWNLOADS]: The skill is designed to fetch external data from arbitrary URLs using the
WebFetchtool and a fallback mechanism involving thegdriveCLI tool. This capability allows the agent to download and process potentially malicious files from untrusted remote sources, which could be used to deliver payloads or malicious instructions. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted external data that could contain malicious instructions designed to manipulate the agent's analysis or report output.
- Ingestion points: Untrusted security reports (PDF, Markdown, JSON, HTML) are ingested in
commands/fix-review.mdandreferences/report-parsing.mdusing theReadandWebFetchtools. Git diffs and commit messages are ingested incommands/fix-review.md(Step 4). - Boundary markers: Absent. The instructions do not require the agent to wrap untrusted content in delimiters or use instructions to ignore embedded commands.
- Capability inventory: The skill possesses the
Bash,Write,WebFetch, andReadtools as listed inSKILL.md. It performs multiple subprocess calls and file-write operations throughout its workflow. - Sanitization: Absent. There are no instructions to validate, sanitize, or filter the content extracted from external reports or repository data before it is processed by the model to determine finding statuses.
Recommendations
- AI detected serious security threats
Audit Metadata