skills/qiniu/skills/appmarket-dev/Gen Agent Trust Hub

appmarket-dev

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Template files and documentation contain examples of downloading and executing remote shell scripts via pipe to bash. These include references to well-known services (NodeSource) and placeholder domains (example.com) for instructional purposes. Evidence is found in assets/setup-image.sh, references/image-building.md, and references/commands/create-app.md.
  • [COMMAND_EXECUTION]: The skill provides Python and Bash CLI tools (appmarket-cli.py, image-cli.py, vm-cli.py, test-module.sh) that execute local shell commands for Terraform operations and remote commands via SSH/sshpass to configure virtual machines. These tools are central to the skill's function but involve executing user-defined scripts and handling passwords in the environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a development assistant that ingests and processes untrusted data (Terraform modules, installation scripts) provided by the user to generate deployment metadata. This presents a vulnerability surface where malicious code within those files could attempt to influence the agent's behavior.
  • Ingestion points: Terraform variables and script contents processed in scripts/tf-to-schema.py and scripts/generate-deploy-meta.sh.
  • Boundary markers: None explicitly implemented for script interpolation.
  • Capability inventory: Local shell execution (Terraform), network requests to vendor APIs (qiniuapi.com), and remote SSH command execution.
  • Sanitization: None observed for script contents; HCL is parsed into JSON Schema structure.
Recommendations
  • HIGH: Downloads and executes remote code from: https://deb.nodesource.com/setup_22.x, https://example.com/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 01:57 AM