cost-compact-context
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a shell command using the Bash tool to run a local Node.js script located at a relative path:
( cd v3 && node ../plugins/ruflo-cost-tracker/scripts/compact.mjs "<QUERY>" ). - [INDIRECT_PROMPT_INJECTION]: The skill interpolates untrusted user input into a shell command template, creating a significant security risk.
- Ingestion points: The
<query>argument provided by the user in SKILL.md. - Boundary markers: The input is wrapped in double quotes in the Bash command, which can be bypassed using common shell metacharacters (e.g., backticks, semicolons, or dollar signs).
- Capability inventory: The skill instructions involve directory traversal and script execution using the Bash tool.
- Sanitization: No input validation or shell-safe escaping is performed on the user-supplied query before execution.
Recommendations
- AI detected serious security threats
Audit Metadata