runtime-behavior-probe
Warn
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill generates TypeScript code and executes it using the ts-node register. It also uses dynamic module loading via import() and createRequire to access repository-level code from temporary locations.
- [COMMAND_EXECUTION]: The skill invokes system commands such as npx tsc for type checking, node for execution, and git for environment metadata through child_process.spawnSync.
- [DATA_EXFILTRATION]: The skill is designed to handle sensitive information like REDIS_PASSWORD from environment variables. While it includes instructions for user approval and secret protection, it possesses the capability to access and transmit this data over a network connection to Redis servers.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external Redis servers which serves as an ingestion point for untrusted content. 1. Ingestion points: Redis command results and event payloads in probe scripts. 2. Boundary markers: The instructions advise capturing raw error types and message prefixes but lack explicit delimiters for prompt interpolation. 3. Capability inventory: Shell command execution (node, tsc, git) and local file writing. 4. Sanitization: No explicit sanitization or filtering of Redis server replies is defined before the agent interprets the results.
Audit Metadata