filesystem-context

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The TerminalCapture class in scripts/filesystem_context.py and references/implementation-patterns.md uses subprocess.run with shell=True to execute arbitrary commands. If the command string is constructed using untrusted input, it poses a risk of command injection.
  • [DYNAMIC_EXECUTION]: The SkillLoader class in references/implementation-patterns.md dynamically resolves and loads instruction files from the filesystem at runtime based on task requirements. This pattern of loading executable instructions from computed paths can be exploited to inject malicious logic into the agent's operational context.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from various external sources, including tool outputs, terminal logs, and sub-agent findings, and re-insert this data into the active prompt context.\n
  • Ingestion points: Files located in scratch/, workspace/agents/, and terminals/ directories are read and included in the prompt.\n
  • Boundary markers: While SKILL.md recommends using summaries and references, the provided Python implementation does not strictly enforce boundary markers or delimiters to isolate ingested content.\n
  • Capability inventory: The skill possesses capabilities for shell command execution (TerminalCapture), file system modification (ScratchPadManager), and directory deletion (shutil.rmtree).\n
  • Sanitization: The PreferenceStore implementation includes basic length validation for keys and values, but other ingestion pathways (such as tool output offloading and terminal log retrieval) lack content sanitization or instruction filtering.
  • [PERSISTENCE]: Pattern 6 in SKILL.md and the PreferenceStore class in references/implementation-patterns.md allow the agent to modify its own configuration files (agent/preferences.yaml). This enables the persistence of instructions or state across different sessions, which could be leveraged to maintain malicious behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 07:13 AM
Security Audit — agent-trust-hub — filesystem-context