filesystem-context
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The
TerminalCaptureclass inscripts/filesystem_context.pyandreferences/implementation-patterns.mdusessubprocess.runwithshell=Trueto execute arbitrary commands. If the command string is constructed using untrusted input, it poses a risk of command injection. - [DYNAMIC_EXECUTION]: The
SkillLoaderclass inreferences/implementation-patterns.mddynamically resolves and loads instruction files from the filesystem at runtime based on task requirements. This pattern of loading executable instructions from computed paths can be exploited to inject malicious logic into the agent's operational context. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from various external sources, including tool outputs, terminal logs, and sub-agent findings, and re-insert this data into the active prompt context.\n
- Ingestion points: Files located in
scratch/,workspace/agents/, andterminals/directories are read and included in the prompt.\n - Boundary markers: While
SKILL.mdrecommends using summaries and references, the provided Python implementation does not strictly enforce boundary markers or delimiters to isolate ingested content.\n - Capability inventory: The skill possesses capabilities for shell command execution (
TerminalCapture), file system modification (ScratchPadManager), and directory deletion (shutil.rmtree).\n - Sanitization: The
PreferenceStoreimplementation includes basic length validation for keys and values, but other ingestion pathways (such as tool output offloading and terminal log retrieval) lack content sanitization or instruction filtering. - [PERSISTENCE]: Pattern 6 in
SKILL.mdand thePreferenceStoreclass inreferences/implementation-patterns.mdallow the agent to modify its own configuration files (agent/preferences.yaml). This enables the persistence of instructions or state across different sessions, which could be leveraged to maintain malicious behavior.
Audit Metadata