monitoring-dashboard
Warn
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill's generator script (
scripts/main.py) creates executable Python code by interpolating user-controlled strings into templates. The functionsgenerate_progress_notebook,generate_test_notebook,generate_traceability_notebook, andgenerate_integrated_notebookuse f-strings to embed thetitleanddata_pathvariables directly into atextwrap.dedentblock. Because these variables are not sanitized or escaped, a crafted input (e.g., using triple quotes or closing parentheses followed by newlines) can break out of the intended string literals to inject and execute arbitrary Python commands when the resulting notebook is opened. - [COMMAND_EXECUTION]: The
SKILL.mdinstructions explicitly direct users to execute the generated, potentially compromised Python script using themarimo runcommand. This effectively bridges the code injection vulnerability to actual system execution. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface (Category 8). It ingests untrusted data from user-specified files and CLI arguments which are then used to dynamically construct executable code.
- Ingestion points: The
--data-sourceand--titlearguments inscripts/main.py, which are populated via agent parameters. - Boundary markers: None. The skill lacks any delimiters or instructions to prevent the interpreter from executing code embedded within these parameters.
- Capability inventory: The generated script has full access to the user's Python environment and filesystem when executed.
- Sanitization: None. The script performs no validation or escaping of the
titleordata_pathvariables before they are written into the output file.
Audit Metadata