rivet-agentos
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill contains numerous examples demonstrating how to run shell commands and manage processes within isolated virtual machines.
- Example scripts such as
examples/host-functions/guest.pyandexamples/processes/exec.tsuse system calls likesubprocess.runandprocess.execto demonstrate interaction with the VM environment. - The
browseCLI skill example provides a management interface for browser automation via shell commands. - [DYNAMIC_EXECUTION]: The platform's ability to execute code at runtime is a primary focus of the examples.
- Multiple examples in
examples/js-quickstart/andexamples/python-quickstart/useevaluate()andexecute()methods to run JavaScript and Python logic inside the guest environment. - The TypeScript example demonstrates checking and transpiling code before execution to ensure validity.
- [EXTERNAL_DOWNLOADS]: The documentation provides instructions for setting up the environment using standard package managers.
- Setup steps include
npm installandnpxfor installing the agentOS SDK and auxiliary tools like thebrowseCLI. - The
browseskill includes functionality to discover and install additional site-specific automation skills from thebrowse.shcatalog. - [INDIRECT_PROMPT_INJECTION]: Several examples involve fetching and processing external web data, which introduces a potential surface for indirect prompt injection.
- Ingestion points: External web content is retrieved using
browse cloud fetchin theexamples/browserbase/integration. - Boundary markers: The provided examples do not explicitly demonstrate the use of delimiters or 'ignore' instructions when processing fetched data.
- Capability inventory: The skill documentation shows that the environment has full capabilities for file system operations, networking, and process execution.
- Sanitization: The examples focus on the mechanics of fetching data rather than the security best practices of sanitizing untrusted input before prompt interpolation.
Audit Metadata