sn-image-resume

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The Worker Agent workflow in SKILL.md constructs shell commands using direct interpolation of user-supplied variables $RESUME_CONTENT and $STYLE (e.g., echo "$RESUME_CONTENT" > ... and cat << EOF). This design allows for potential command injection if the agent execution environment does not properly sanitize these variables, enabling an attacker to execute arbitrary shell commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input into an LLM prompt without proper isolation, exposing the system to prompt injection attacks.\n
  • Ingestion points: The resume_content parameter in SKILL.md.\n
  • Boundary markers: Absent; the content is placed directly in the USER_PROMPT heredoc without delimiters or instructions to ignore embedded commands.\n
  • Capability inventory: Spawning subprocesses via python for sn_agent_runner.py, writing files to the /tmp directory, and performing network operations via text and image generation APIs.\n
  • Sanitization: Absent; no filtering or escaping is applied to the input text before prompt construction.\n- [DATA_EXFILTRATION]: The skill documentation identifies and utilizes sensitive environment variables for authentication, such as SN_API_KEY. If a command or prompt injection occurs, these credentials could be compromised and exfiltrated to external endpoints during the generation process.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 08:18 AM
Security Audit — agent-trust-hub — sn-image-resume