anachb
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The shell scripts
search.sh,departures.sh, androute.shconstruct JSON request bodies by directly interpolating user-provided arguments into the payload. This lack of validation or escaping creates a JSON injection surface where special characters in the input could be used to manipulate the API request parameters. - [EXTERNAL_DOWNLOADS]: The skill performs network requests to
https://vao.demo.hafas.de/gateusingcurlto fetch transport information. This is expected behavior for the service described and targets a known transport API. - [SAFE]: No evidence of hardcoded credentials, persistence mechanisms, or unauthorized file system operations was found in the skill's code.
Audit Metadata