smoke-test

Warn

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a phase where it prioritizes instructions from untrusted repository files, creating an indirect prompt injection surface. Ingestion points: SMOKETEST.md, .smoketest.md, and README.md (Phase 0). Boundary markers: None; instructions state external files should 'override' and be treated as 'authoritative'. Capability inventory: Shell access for tools like curl, psql, and aws s3 (References). Sanitization: None.
  • [DATA_EXFILTRATION]: The skill accesses sensitive environment configuration and infrastructure credentials. Phase 3 in SKILL.md instructs the agent to 'Discover ports, env, and credentials from the repo'. references/signals.md instructs querying database rows, blob storage, and process logs.
  • [COMMAND_EXECUTION]: The workflow executes shell commands to drive applications and verify infrastructure, with parameters influenced by untrusted repo files. references/entrypoints.md and references/signals.md suggest using curl, psql, aws s3, and redis-cli to interact with real systems.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 07:17 PM
Security Audit — agent-trust-hub — smoke-test