nocobase-env-manage

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to prioritize and follow instructions from user-provided "official NocoBase install" URLs over its own internal command tables. This creates a vulnerability where a malicious URL could contain instructions that trick the agent into performing unauthorized actions.
  • Ingestion points: User-provided installation URLs and output from nb app logs.
  • Boundary markers: Absent; there are no specific instructions to treat external URL content as untrusted data or to wrap it in safety delimiters.
  • Capability inventory: Full access to the nb CLI (init, app, env, self, skills) and general shell access via the Bash tool.
  • Sanitization: No content validation or sanitization is performed on the data fetched from external URLs before the agent processes it as instructions.
  • [COMMAND_EXECUTION]: The skill is designed to execute a wide array of administrative shell commands through the nb CLI tool, including environment bootstrap, application lifecycle management, and system updates. While the skill prohibits running local script files, the broad interface of the nb binary allows for significant system-level changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:43 PM
Security Audit — agent-trust-hub — nocobase-env-manage