astro-cta-injector
Warn
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external content files (.astro, .md) to identify placement locations for CTAs. This creates a surface for indirect prompt injection if the files contain malicious instructions designed to influence the agent's scoring or injection logic.
- Ingestion points:
scripts/score_posts.pyandscripts/inject_ctas.pyread content from local blog post files. - Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious embedded content within the files being processed.
- Capability inventory:
scripts/inject_ctas.pyperforms file write operations to the local content directory. - Sanitization: While
BeautifulSoupis used to strip tags for scoring, the injection process uses raw string replacement without sanitizing the original file content. - [DYNAMIC_EXECUTION]: Both
scripts/inject_ctas.pyandscripts/score_posts.pymodify the Python search path (sys.path) at runtime to load shared modules from a relative path (../../../../shared). - Evidence:
sys.path.insert(0, str(Path(__file__).parent.parent.parent.parent / "shared"))is used to loadconfig_loaderandutils. - Risk: Loading modules from computed relative paths can be exploited if the directory structure is manipulated, potentially leading to the execution of unintended code.
- [COMMAND_EXECUTION]: The skill instructs the user to run Python scripts that perform file system modifications and backups.
- Evidence:
scripts/inject_ctas.pyperformsshutil.copy2for backups and usesopen(file_path, 'w')to overwrite content files when the--applyflag is used.
Audit Metadata