qa-test-planner

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The bash scripts scripts/create_bug_report.sh and scripts/generate_test_cases.sh contain a command injection vulnerability. The prompt_input function uses eval to assign user-provided input to internal variables without sanitization or escaping.
  • Evidence: The line eval "$var_name=\"$input\"" in both scripts is vulnerable. If the $input variable contains shell metacharacters such as backticks or the $(...) syntax, the shell will execute those commands in the context of the script.
  • Impact: This allows any data processed by these scripts to potentially trigger arbitrary code execution on the user's system.
  • [PROMPT_INJECTION]: The skill exhibits a significant surface for indirect prompt injection because it ingests untrusted data and passes it to the vulnerable eval command.
  • Ingestion points: User-supplied text for bug descriptions, titles, and test steps in scripts/create_bug_report.sh and scripts/generate_test_cases.sh.
  • Boundary markers: Absent. There are no delimiters or instructions to treat the input as data only.
  • Capability inventory: The skill can execute shell commands via the vulnerable scripts and write files to the local directory.
  • Sanitization: Absent. The scripts perform no validation or escaping of the input before processing it with eval.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 09:40 PM
Security Audit — agent-trust-hub — qa-test-planner