apex-replatform
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The validation scripts (
scripts/validate.shandscripts/validate.ps1) utilizeevalandInvoke-Expressionto execute commands. These commands are constructed dynamically based on the project's environment and configuration files (e.g., detecting package managers or reading script names frompackage.json). This pattern of dynamic code execution can be leveraged to run unintended commands if project metadata is manipulated. - [COMMAND_EXECUTION]: The skill provides automated routines to execute a variety of development tools, including linter, type checkers, and test runners (e.g., npm, pytest, go vet, cargo). These tools execute within the context of the project directory and can trigger arbitrary scripts defined in local configuration files.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow is driven by reading and implementing logic from external specification files (
specs/{feature-name}.md). If these files contain malicious instructions, the agent may implement unsafe code or modify project configuration files that are subsequently executed by the validation scripts. - Ingestion points: Specification files are read from the
specs/directory at the start of the workflow. - Boundary markers: The skill does not employ specific delimiters or system instructions to ignore potential injection within the specs.
- Capability inventory: The agent can write files to the project directory and execute shell commands via the provided validation scripts.
- Sanitization: There is no automated sanitization of the input specification content before it influences code generation or script execution.
Audit Metadata