content-brief-generator
Warn
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/generate_brief.shcontains a command injection vulnerability. It uses theevalcommand to process user-provided input without proper sanitization. Specifically, the functionsprompt_inputandprompt_multilineexecuteeval "$var_name=\"$input\"". If the input contains shell metacharacters such as backticks,$(...), or semicolons, these will be executed by the shell environment. - [DYNAMIC_EXECUTION]: The script uses
evalto dynamically assign variables at runtime based on user input. This pattern is inherently unsafe as it treats data as code, enabling the execution of arbitrary shell commands if the input is manipulated. - [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves an interactive script that ingests external data to generate a document. This creates a vulnerability surface where untrusted data processed by an agent could contain payloads designed to exploit the command injection flaw in
scripts/generate_brief.sh. - Ingestion points: User input prompts in
scripts/generate_brief.shvia thereadcommand. - Boundary markers: None; the script directly assigns input to variables.
- Capability inventory: The script performs file writing (
cat > "$OUTPUT_FILE") and variable evaluation (eval). - Sanitization: The script performs basic sanitization on the filename (
FILENAME="${TITLE// /_}"), but the content of the variables remains unsanitized when passed toeval.
Audit Metadata