dgx-station
Warn
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a shell script
scripts/dgx-assistto perform system inspections and search for platform playbooks. - Evidence:
SKILL.mdandreferences/cli.mdinstruct the agent to runscripts/dgx-assist system inspectandscripts/dgx-assist playbook search. - [DYNAMIC_EXECUTION]: The script
scripts/dgx-assistimplements dynamic execution logic that can be manipulated via environment variables or relative pathing. - Evidence: The script checks for the
DGX_ASSIST_BINenvironment variable and executes its value if present. It also falls back to a relative path../../../../.dgx-station/bin/dgx-assistwhich targets a location outside the skill's directory structure. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data retrieved via the playbook search functionality, which could contain malicious instructions.
- Ingestion points: Results from
scripts/dgx-assist playbook searchandscripts/dgx-assist playbook showinSKILL.md. - Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions embedded within the retrieved passages.
- Capability inventory: The skill has the ability to execute shell commands via the
dgx-assistscript (documented inreferences/cli.md). - Sanitization: No sanitization or validation of the retrieved playbook content is performed before it is used to generate the final response.
Audit Metadata