logifleet-pulse-supply-chain-analytics

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from an unverified GitHub account (Empty5i/LogiCore-Analytics-Adaptive-Supply-Chain-Pulse) to obtain the core SQL schema and deployment scripts.
  • [COMMAND_EXECUTION]: The deployment process involves high-privilege command execution, including shell commands for cloning repositories, SQL script execution (:r deploy_schema.sql) via SSMS/SQLCMD, and PowerShell module installation (MicrosoftPowerBIMgmt) for cloud deployment.
  • [PERSISTENCE]: The skill establishes persistence by creating SQL Server Agent jobs (sp_add_job) that run on a scheduled basis. Specifically, the LogiFleet_CriticalAlerts job executes every 15 minutes to perform data analysis and send automated emails, which could be abused if the underlying logic is modified.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection through its data ingestion patterns.
  • Ingestion points: Processes external data from WMS systems via OPENQUERY and fetches JSON telemetry data from a remote REST API via sp_InvokeRESTAPI and OPENJSON.
  • Boundary markers: No boundary markers or instruction-ignoring delimiters are used when processing external strings.
  • Capability inventory: The skill possesses the ability to write to the database, trigger automated emails via sp_send_dbmail, and publish configurations to Power BI Service via PowerShell.
  • Sanitization: There is no evidence of sanitization or validation of the external API responses or WMS query results before they are processed by the stored procedures or interpolated into reporting logic.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — logifleet-pulse-supply-chain-analytics