datadog
Warn
Audited by Gen Agent Trust Hub on Apr 24, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
runCommandfunction inskill.jsconstructs shell commands for thedogCLI by joining an array of arguments with spaces (.join(" ")). Because these arguments include raw user input from parameters such asquery(inmetric-query),title(inevent-post), andmessage(inhost-mute), a user or a malicious data source could provide input containing shell metacharacters (e.g.,;,&,|,$(...)) to execute arbitrary commands. Since the skill is configured withallowed-tools: Bash, these generated commands are likely executed in a shell environment, leading to a command injection vulnerability. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data that is directly used to generate executable shell commands.
- Ingestion points: All tool parameters in
skill.jsthat accept strings, includingquery,name,tags,title,text,hostname,message, andscope. - Boundary markers: Absent. The skill does not implement any delimiters or instructions to treat the ingested data as literal strings rather than executable logic.
- Capability inventory: The skill is designed to interact with the host system via the
dogCLI and is explicitly allowed to use theBashtool. - Sanitization: Absent. No shell-quoting, escaping, or character validation is performed on the input arguments before they are joined into a command string.
Audit Metadata