appmarket-dev
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Template files and documentation contain examples of downloading and executing remote shell scripts via pipe to bash. These include references to well-known services (NodeSource) and placeholder domains (example.com) for instructional purposes. Evidence is found in
assets/setup-image.sh,references/image-building.md, andreferences/commands/create-app.md. - [COMMAND_EXECUTION]: The skill provides Python and Bash CLI tools (
appmarket-cli.py,image-cli.py,vm-cli.py,test-module.sh) that execute local shell commands for Terraform operations and remote commands via SSH/sshpass to configure virtual machines. These tools are central to the skill's function but involve executing user-defined scripts and handling passwords in the environment. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a development assistant that ingests and processes untrusted data (Terraform modules, installation scripts) provided by the user to generate deployment metadata. This presents a vulnerability surface where malicious code within those files could attempt to influence the agent's behavior.
- Ingestion points: Terraform variables and script contents processed in
scripts/tf-to-schema.pyandscripts/generate-deploy-meta.sh. - Boundary markers: None explicitly implemented for script interpolation.
- Capability inventory: Local shell execution (Terraform), network requests to vendor APIs (
qiniuapi.com), and remote SSH command execution. - Sanitization: None observed for script contents; HCL is parsed into JSON Schema structure.
Recommendations
- HIGH: Downloads and executes remote code from: https://deb.nodesource.com/setup_22.x, https://example.com/install.sh - DO NOT USE without thorough review
Audit Metadata