cost-compact-context

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a shell command using the Bash tool to run a local Node.js script located at a relative path: ( cd v3 && node ../plugins/ruflo-cost-tracker/scripts/compact.mjs "<QUERY>" ).
  • [INDIRECT_PROMPT_INJECTION]: The skill interpolates untrusted user input into a shell command template, creating a significant security risk.
  • Ingestion points: The <query> argument provided by the user in SKILL.md.
  • Boundary markers: The input is wrapped in double quotes in the Bash command, which can be bypassed using common shell metacharacters (e.g., backticks, semicolons, or dollar signs).
  • Capability inventory: The skill instructions involve directory traversal and script execution using the Bash tool.
  • Sanitization: No input validation or shell-safe escaping is performed on the user-supplied query before execution.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — cost-compact-context