monitoring-dashboard

Warn

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill's generator script (scripts/main.py) creates executable Python code by interpolating user-controlled strings into templates. The functions generate_progress_notebook, generate_test_notebook, generate_traceability_notebook, and generate_integrated_notebook use f-strings to embed the title and data_path variables directly into a textwrap.dedent block. Because these variables are not sanitized or escaped, a crafted input (e.g., using triple quotes or closing parentheses followed by newlines) can break out of the intended string literals to inject and execute arbitrary Python commands when the resulting notebook is opened.
  • [COMMAND_EXECUTION]: The SKILL.md instructions explicitly direct users to execute the generated, potentially compromised Python script using the marimo run command. This effectively bridges the code injection vulnerability to actual system execution.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface (Category 8). It ingests untrusted data from user-specified files and CLI arguments which are then used to dynamically construct executable code.
  • Ingestion points: The --data-source and --title arguments in scripts/main.py, which are populated via agent parameters.
  • Boundary markers: None. The skill lacks any delimiters or instructions to prevent the interpreter from executing code embedded within these parameters.
  • Capability inventory: The generated script has full access to the user's Python environment and filesystem when executed.
  • Sanitization: None. The script performs no validation or escaping of the title or data_path variables before they are written into the output file.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 14, 2026, 05:59 AM
Security Audit — agent-trust-hub — monitoring-dashboard