sn-image-resume
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The Worker Agent workflow in
SKILL.mdconstructs shell commands using direct interpolation of user-supplied variables$RESUME_CONTENTand$STYLE(e.g.,echo "$RESUME_CONTENT" > ...andcat << EOF). This design allows for potential command injection if the agent execution environment does not properly sanitize these variables, enabling an attacker to execute arbitrary shell commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input into an LLM prompt without proper isolation, exposing the system to prompt injection attacks.\n - Ingestion points: The
resume_contentparameter inSKILL.md.\n - Boundary markers: Absent; the content is placed directly in the
USER_PROMPTheredoc without delimiters or instructions to ignore embedded commands.\n - Capability inventory: Spawning subprocesses via
pythonforsn_agent_runner.py, writing files to the/tmpdirectory, and performing network operations via text and image generation APIs.\n - Sanitization: Absent; no filtering or escaping is applied to the input text before prompt construction.\n- [DATA_EXFILTRATION]: The skill documentation identifies and utilizes sensitive environment variables for authentication, such as
SN_API_KEY. If a command or prompt injection occurs, these credentials could be compromised and exfiltrated to external endpoints during the generation process.
Audit Metadata