threat-model
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
scripts/trace-data-flows.shscript is susceptible to indirect prompt injection because it ingests directory names from the analyzed project and uses them in a command context without sanitization.\n - Ingestion points: Filesystem paths and directory names are read from the project root using
rg -landdirnamewithinscripts/trace-data-flows.sh.\n - Boundary markers: None provided in the script to delimit untrusted filesystem data.\n
- Capability inventory: The script utilizes shell command execution and spawns a Python interpreter to calculate relative paths.\n
- Sanitization: Absent. The script interpolates the
$dirvariable into apython3 -ccommand using single quotes ('$dir'). A directory name containing a single quote and Python code (e.g.,';import os;os.system("id");') would execute arbitrary code during the analysis phase.\n- [COMMAND_EXECUTION]: The scriptscripts/trace-data-flows.shcontains an unsafe command execution pattern. It passes shell variables directly into a Python expression string evaluated bypython3 -c. This pattern facilitates arbitrary code execution when the input (directory names) is not strictly controlled.
Audit Metadata