skills/openfunnel/openfunnel-skills/spot-companies-and-people-with-active-pain-points/Gen Agent Trust Hub
spot-companies-and-people-with-active-pain-points
Fail
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Shell command injection vulnerability in
signup.sh. The script interpolates the$EMAILvariable directly into acurlcommand's data parameter without adequate quoting or sanitization. A crafted input containing shell metacharacters (e.g., semicolons or backticks) could terminate the intended command and execute arbitrary shell instructions.\n- [COMMAND_EXECUTION]: Potential command substitution vulnerability inapi.sh. The script uses the$BODYvariable within double quotes in acurlcommand string. This allows the shell to evaluate and execute embedded command substitution patterns, such as$(...), if they are present in the JSON payload constructed by the agent.
Recommendations
- AI detected serious security threats
Audit Metadata