spot-companies-and-people-with-active-pain-points

Fail

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Shell command injection vulnerability in signup.sh. The script interpolates the $EMAIL variable directly into a curl command's data parameter without adequate quoting or sanitization. A crafted input containing shell metacharacters (e.g., semicolons or backticks) could terminate the intended command and execute arbitrary shell instructions.\n- [COMMAND_EXECUTION]: Potential command substitution vulnerability in api.sh. The script uses the $BODY variable within double quotes in a curl command string. This allows the shell to evaluate and execute embedded command substitution patterns, such as $(...), if they are present in the JSON payload constructed by the agent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 20, 2026, 09:29 AM
Security Audit — agent-trust-hub — spot-companies-and-people-with-active-pain-points