skills/othmanadi/apex/apex-tier1/Gen Agent Trust Hub

apex-tier1

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The validation scripts (scripts/validate.sh and scripts/validate.ps1) use dynamic command execution. In validate.sh, the run_step function uses eval "$cmd", where $cmd is constructed from strings like npm run lint or npx eslint. In validate.ps1, Invoke-Expression is used for similar purposes. While these commands are largely derived from static strings or local configuration files (package.json), they represent a shell execution surface that could be exploited if an attacker can influence the project's build configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted task descriptions from the user to generate pull request bodies and branch names.
  • Ingestion points: SKILL.md instructs the agent to parse a user-provided task description into acceptance criteria and use it in gh pr create commands.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are provided when processing the task description.
  • Capability inventory: The skill has capabilities for file system modification (git), network operations via CLI (gh pr create, git push), and local script execution (scripts/validate.sh).
  • Sanitization: There is no evidence of sanitization for the {task description} or {task-slug} before they are passed to shell commands like git checkout -b or gh pr create. An attacker-crafted task name could potentially lead to command injection if the agent does not properly escape the input.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:43 AM
Security Audit — agent-trust-hub — apex-tier1