nocobase-env-manage
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to prioritize and follow instructions from user-provided "official NocoBase install" URLs over its own internal command tables. This creates a vulnerability where a malicious URL could contain instructions that trick the agent into performing unauthorized actions.
- Ingestion points: User-provided installation URLs and output from
nb app logs. - Boundary markers: Absent; there are no specific instructions to treat external URL content as untrusted data or to wrap it in safety delimiters.
- Capability inventory: Full access to the
nbCLI (init, app, env, self, skills) and general shell access via theBashtool. - Sanitization: No content validation or sanitization is performed on the data fetched from external URLs before the agent processes it as instructions.
- [COMMAND_EXECUTION]: The skill is designed to execute a wide array of administrative shell commands through the
nbCLI tool, including environment bootstrap, application lifecycle management, and system updates. While the skill prohibits running local script files, the broad interface of thenbbinary allows for significant system-level changes.
Audit Metadata