dsh-benchmark-case

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEPROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill mandates the inclusion of a standardized authorization block called 'BENCHMARK-AUTH-v1' in generated tasks. This block contains explicit instructions to bypass standard AI safety and interaction patterns, such as 'there will be no follow-up user messages', 'continue executing immediately once the plan is formed', 'do not pause to wait for "confirmation"', and 'do not stop merely because another round of confirmation is missing'. While intended for automated benchmarking, these are structural overrides of default agent constraints.
  • [DYNAMIC_EXECUTION]: The skill's core functionality involves generating and executing scripts at runtime. The judge-utils.mjs file provides utilities that use execFile('sh', ['-c', script]) and node -e to execute dynamically generated code for grading purposes. It also uses Base64 encoding to write files via shell redirection, a technique often used to bypass character restrictions in command execution.
  • [COMMAND_EXECUTION]: The skill performs extensive shell operations within the task container, including process management (pkill), file system manipulation (rm -rf), and version control (git). The documentation provides specific advice on using command-line tricks (like the [x] bracket pattern for pkill) to ensure high-privilege operations do not accidentally terminate the grading process itself.
  • [EXTERNAL_DOWNLOADS]: The skill configures its environment by downloading specific packages from the npm registry, including @deepseek-ai/dsh and pnpm. While these target well-known organizations, the skill also processes external, user-provided plugin repositories to extract content for task generation, which serves as a potential vector for indirect injection or malicious content ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 06:18 AM