hosted-agents
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill's reference implementations and scripts construct shell commands using direct string interpolation of potentially untrusted variables without sanitization.\n
- In
references/infrastructure-patterns.md,os.systemis used to execute commands where repository URLs and user identities are interpolated:os.system(f\"git clone https://x-access-token:{token}@github.com/{self.repo_url}\")andos.system(f'git config user.name \"{user_identity[\"name\"]}\"').\n - In
scripts/sandbox_manager.py, theImageBuilderclass and_configure_for_usermethod construct shell strings using f-strings for repository cloning and git configuration.\n - Constructing shell commands in this manner allows for arbitrary command execution if an attacker provides malicious inputs for the repository URL, user name, or email fields.\n- [INDIRECT_PROMPT_INJECTION]: The skill architecture facilitates the ingestion and processing of untrusted data from external repositories and user messages in environments with significant capabilities, creating a vulnerability to indirect prompt injection.\n
- Ingestion points: Repository contents are processed during the
ImageBuilderpipeline, and user messages are ingested via Slack and Chrome extensions.\n - Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within the processed data.\n
- Capability inventory: The sandboxed environments are designed with full shell access, filesystem read/write permissions, and network access to APIs like GitHub and Modal.\n
- Sanitization: No validation or sanitization of external repository content or user-supplied metadata is implemented in the provided patterns.\n- [CREDENTIALS_UNSAFE]: The repository cloning pattern involves embedding short-lived GitHub authentication tokens directly into the URL passed to shell commands.\n
- Evidence in
references/infrastructure-patterns.md:git clone https://x-access-token:{token}@github.com/{self.repo_url}.\n - Passing credentials as part of a command-line argument can lead to token exposure in process monitoring tools, system logs, or shell history within the execution environment.\n- [EXTERNAL_DOWNLOADS]: The skill implements patterns for fetching code and dependencies from external sources.\n
- It uses
git cloneto pull repository content from GitHub and utilizesnpm installandpip installto manage runtime environments.\n - Dependencies fetched via
pipincludeopencode,gitpython, andpsycopg2-binary.\n - While these operations target established platforms like GitHub, npm, and PyPI, the specific repository targets are dynamically determined at runtime based on user configuration.
Recommendations
- AI detected serious security threats
Audit Metadata