eu-sparql-search

Fail

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions explicitly direct the agent to subvert platform security controls and tool restrictions.
  • Evidence: "This bypasses all web_fetch permission restrictions and works unconditionally"
  • Evidence: "Do NOT use web_fetch for Cellar URLs... Use curl in bash_tool instead."
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the bash_tool to execute shell commands and Python scripts for network access, despite bash_tool being restricted by the skill's frontmatter allowed-tools configuration. It also provides a code snippet to disable SSL certificate verification (ssl.CERT_NONE), facilitating insecure network connections and potential man-in-the-middle attacks.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 14, 2026, 08:28 AM
Security Audit — agent-trust-hub — eu-sparql-search