enterprise-user-management-system-ai
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to clone source code from a third-party GitHub repository (
github.com/Nareshkumar2583/Enterprise-User-Management-System-with-AI-Analytics) that is not associated with the skill author or a recognized trusted organization. - [REMOTE_CODE_EXECUTION]: Following the clone operation, the skill provides instructions to execute
npm installandpip install -r requirements.txt, followed by launching the backend and ML services. This constitutes execution of unverified remote code in the user's environment. - [INDIRECT_PROMPT_INJECTION]: The skill describes a system for processing user-supplied support tickets and task data using AI analytics modules, creating an attack surface for data-driven injections.
- Ingestion points: Ticket titles and descriptions are ingested at the
/api/ml/classify-ticketendpoint inml-service/main.py. - Boundary markers: No delimiters or instructions to ignore embedded commands are present in the processing logic.
- Capability inventory: The system interacts with a MongoDB database and performs automated classification/risk assessment.
- Sanitization: The rule-based classification logic concatenates title and description fields without filtering or validation against prompt injection patterns.
Recommendations
- AI detected serious security threats
Audit Metadata