hosted-agents

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill's reference implementations and scripts construct shell commands using direct string interpolation of potentially untrusted variables without sanitization.\n
  • In references/infrastructure-patterns.md, os.system is used to execute commands where repository URLs and user identities are interpolated: os.system(f\"git clone https://x-access-token:{token}@github.com/{self.repo_url}\") and os.system(f'git config user.name \"{user_identity[\"name\"]}\"').\n
  • In scripts/sandbox_manager.py, the ImageBuilder class and _configure_for_user method construct shell strings using f-strings for repository cloning and git configuration.\n
  • Constructing shell commands in this manner allows for arbitrary command execution if an attacker provides malicious inputs for the repository URL, user name, or email fields.\n- [INDIRECT_PROMPT_INJECTION]: The skill architecture facilitates the ingestion and processing of untrusted data from external repositories and user messages in environments with significant capabilities, creating a vulnerability to indirect prompt injection.\n
  • Ingestion points: Repository contents are processed during the ImageBuilder pipeline, and user messages are ingested via Slack and Chrome extensions.\n
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within the processed data.\n
  • Capability inventory: The sandboxed environments are designed with full shell access, filesystem read/write permissions, and network access to APIs like GitHub and Modal.\n
  • Sanitization: No validation or sanitization of external repository content or user-supplied metadata is implemented in the provided patterns.\n- [CREDENTIALS_UNSAFE]: The repository cloning pattern involves embedding short-lived GitHub authentication tokens directly into the URL passed to shell commands.\n
  • Evidence in references/infrastructure-patterns.md: git clone https://x-access-token:{token}@github.com/{self.repo_url}.\n
  • Passing credentials as part of a command-line argument can lead to token exposure in process monitoring tools, system logs, or shell history within the execution environment.\n- [EXTERNAL_DOWNLOADS]: The skill implements patterns for fetching code and dependencies from external sources.\n
  • It uses git clone to pull repository content from GitHub and utilizes npm install and pip install to manage runtime environments.\n
  • Dependencies fetched via pip include opencode, gitpython, and psycopg2-binary.\n
  • While these operations target established platforms like GitHub, npm, and PyPI, the specific repository targets are dynamically determined at runtime based on user configuration.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 05:03 PM
Security Audit — agent-trust-hub — hosted-agents