skills/marcioaltoe/skills/qa-report/Gen Agent Trust Hub

qa-report

Fail

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The shell scripts scripts/create_bug_report.sh and scripts/generate_test_cases.sh utilize the eval command within the prompt_input function to dynamically assign user-provided input to shell variables. This implementation is highly vulnerable to command injection as it does not sanitize shell metacharacters. An attacker could provide input containing command substitution or other shell-active sequences to execute arbitrary commands on the system.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 16, 2026, 02:37 PM
Security Audit — agent-trust-hub — qa-report