asset-manager

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The font optimization script provided in references/font-management.md utilizes child_process.exec to run external binaries. The input variable, containing file paths derived from fs.readdir, is interpolated directly into the shell command strings (woff2_compress ${input} and sfnt2woff ${input}) without any escaping or sanitization. This pattern allows for command injection if a file in the input directory has a name containing shell metacharacters.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an automated asset processing pipeline that ingests data from the local file system, creating an attack surface for indirect injection via malicious file naming.
  • Ingestion points: references/font-management.md, references/image-optimization.md, and references/organization.md all use fs.readdir to read files from the project directory.
  • Boundary markers: None are present to delimit or validate the filenames before processing.
  • Capability inventory: The skill uses child_process.exec for font compression, fs.rename for file organization, and fs.writeFile for generating optimized versions and manifest files.
  • Sanitization: Filenames are used directly in shell commands and file system operations without sanitization or validation against allowed patterns.
  • [DYNAMIC_EXECUTION]: The skill provides logic to dynamically invoke command-line tools (woff2_compress, sfnt2woff) at runtime based on the contents of the asset directories, which facilitates the execution of code outside the primary agent environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:50 AM
Security Audit — agent-trust-hub — asset-manager