apex-tier3
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The validation scripts utilize dynamic execution methods to run project-specific tasks.
- The Bash script
scripts/validate.shuses theevalcommand to execute shell strings constructed from the project's environment. - The PowerShell script
scripts/validate.ps1uses theInvoke-Expressioncmdlet to execute commands. - [COMMAND_EXECUTION]: The skill executes shell and PowerShell commands as part of its "Validation Chain." These commands are derived from files within the project directory being analyzed.
- In
validate.sh, commands for linting, testing, and building are extracted from thescriptssection ofpackage.jsonand executed. - In
validate.ps1, similar logic is used to extract and execute commands via PowerShell. - [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and executes data from potentially untrusted project configuration files.
- Ingestion points: The scripts read and parse
package.json,pyproject.toml,requirements.txt,go.mod, andCargo.tomlfrom the target project directory. - Boundary markers: No boundary markers or "ignore instructions" warnings are present when processing these configuration files.
- Capability inventory: The skill has the capability to execute arbitrary shell and PowerShell commands, as well as read files and write to the console.
- Sanitization: The scripts do not perform validation or sanitization on the command strings retrieved from configuration files before passing them to the execution engine (
evalorInvoke-Expression).
Audit Metadata