content-brief-generator

Warn

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/generate_brief.sh contains a command injection vulnerability. It uses the eval command to process user-provided input without proper sanitization. Specifically, the functions prompt_input and prompt_multiline execute eval "$var_name=\"$input\"". If the input contains shell metacharacters such as backticks, $(...), or semicolons, these will be executed by the shell environment.
  • [DYNAMIC_EXECUTION]: The script uses eval to dynamically assign variables at runtime based on user input. This pattern is inherently unsafe as it treats data as code, enabling the execution of arbitrary shell commands if the input is manipulated.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves an interactive script that ingests external data to generate a document. This creates a vulnerability surface where untrusted data processed by an agent could contain payloads designed to exploit the command injection flaw in scripts/generate_brief.sh.
  • Ingestion points: User input prompts in scripts/generate_brief.sh via the read command.
  • Boundary markers: None; the script directly assigns input to variables.
  • Capability inventory: The script performs file writing (cat > "$OUTPUT_FILE") and variable evaluation (eval).
  • Sanitization: The script performs basic sanitization on the filename (FILENAME="${TITLE// /_}"), but the content of the variables remains unsanitized when passed to eval.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 25, 2026, 08:03 AM
Security Audit — agent-trust-hub — content-brief-generator