meshy-openclaw

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documentation provides Bash command recipes that interpolate untrusted user data (3D generation prompts) directly into shell commands and JSON payloads without sanitization or escaping.
  • Ingestion points: In references/pipelines.md, user prompts are assigned to variables and used to construct command-line arguments for scripts/meshy_task.py.
  • Boundary markers: The skill does not employ boundary markers or specific instructions to the agent to ignore potentially malicious embedded commands in the user prompt.
  • Capability inventory: The skill possesses the capability to perform network requests via scripts/meshy_task.py and execute shell commands to launch external applications via scripts/slicers.py.
  • Sanitization: There is no evidence of prompt sanitization, character escaping, or validation before interpolation into the Bash execution context.
  • [COMMAND_EXECUTION]: The scripts/slicers.py utility uses subprocess.run and subprocess.Popen to launch 3D printing slicer software. While this is the intended purpose of the skill, the execution of external binaries based on filesystem detection and command-line arguments presents a capability that could be misused if the input file paths are not properly validated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:02 PM
Security Audit — agent-trust-hub — meshy-openclaw