astro-cta-injector

Warn

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external content files (.astro, .md) to identify placement locations for CTAs. This creates a surface for indirect prompt injection if the files contain malicious instructions designed to influence the agent's scoring or injection logic.
  • Ingestion points: scripts/score_posts.py and scripts/inject_ctas.py read content from local blog post files.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore potentially malicious embedded content within the files being processed.
  • Capability inventory: scripts/inject_ctas.py performs file write operations to the local content directory.
  • Sanitization: While BeautifulSoup is used to strip tags for scoring, the injection process uses raw string replacement without sanitizing the original file content.
  • [DYNAMIC_EXECUTION]: Both scripts/inject_ctas.py and scripts/score_posts.py modify the Python search path (sys.path) at runtime to load shared modules from a relative path (../../../../shared).
  • Evidence: sys.path.insert(0, str(Path(__file__).parent.parent.parent.parent / "shared")) is used to load config_loader and utils.
  • Risk: Loading modules from computed relative paths can be exploited if the directory structure is manipulated, potentially leading to the execution of unintended code.
  • [COMMAND_EXECUTION]: The skill instructs the user to run Python scripts that perform file system modifications and backups.
  • Evidence: scripts/inject_ctas.py performs shutil.copy2 for backups and uses open(file_path, 'w') to overwrite content files when the --apply flag is used.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 25, 2026, 08:04 AM
Security Audit — agent-trust-hub — astro-cta-injector