meshy-openclaw
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documentation provides Bash command recipes that interpolate untrusted user data (3D generation prompts) directly into shell commands and JSON payloads without sanitization or escaping.
- Ingestion points: In
references/pipelines.md, user prompts are assigned to variables and used to construct command-line arguments forscripts/meshy_task.py. - Boundary markers: The skill does not employ boundary markers or specific instructions to the agent to ignore potentially malicious embedded commands in the user prompt.
- Capability inventory: The skill possesses the capability to perform network requests via
scripts/meshy_task.pyand execute shell commands to launch external applications viascripts/slicers.py. - Sanitization: There is no evidence of prompt sanitization, character escaping, or validation before interpolation into the Bash execution context.
- [COMMAND_EXECUTION]: The
scripts/slicers.pyutility usessubprocess.runandsubprocess.Popento launch 3D printing slicer software. While this is the intended purpose of the skill, the execution of external binaries based on filesystem detection and command-line arguments presents a capability that could be misused if the input file paths are not properly validated.
Audit Metadata