recall

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill constructs a shell command by interpolating user-provided arguments directly into a query string. Evidence: The command template uv run python scripts/core/recall_learnings.py --query "<ARGS>" in SKILL.md allows an attacker to break out of the double quotes (e.g., using ";") and execute arbitrary shell commands on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and displays the full content of past learnings from a database which could contain untrusted data or malicious instructions. Ingestion points: PostgreSQL database retrieved via scripts/core/recall_learnings.py. Boundary markers: No delimiters or warnings are used to separate retrieved content from agent instructions. Capability inventory: The skill has access to shell execution via uv. Sanitization: No content filtering or sanitization is mentioned for the retrieved data.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — recall