recall
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill constructs a shell command by interpolating user-provided arguments directly into a query string. Evidence: The command template
uv run python scripts/core/recall_learnings.py --query "<ARGS>"in SKILL.md allows an attacker to break out of the double quotes (e.g., using ";") and execute arbitrary shell commands on the host system. - [INDIRECT_PROMPT_INJECTION]: The skill retrieves and displays the full content of past learnings from a database which could contain untrusted data or malicious instructions. Ingestion points: PostgreSQL database retrieved via scripts/core/recall_learnings.py. Boundary markers: No delimiters or warnings are used to separate retrieved content from agent instructions. Capability inventory: The skill has access to shell execution via uv. Sanitization: No content filtering or sanitization is mentioned for the retrieved data.
Recommendations
- AI detected serious security threats
Audit Metadata