wizard
Warn
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to read sensitive local files, specifically .env, .env.example, .env.*, and GitHub workflow files in .github/workflows/. These files typically contain or define sensitive API keys and secret configurations, and reading them into the agent's context poses a risk of data exposure.\n- [DYNAMIC_EXECUTION]: The skill generates an executable bash script by combining a predefined template with agent-generated logic. The agent is then instructed to mark the script as executable (chmod +x) and provide instructions for the user to run it, which is a form of dynamic code generation.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted repository sources, such as README files and framework configurations, to drive its logic.\n
- Ingestion points: README, .github/workflows/, docker-compose, and various framework configuration files.\n
- Boundary markers: None; the instructions do not specify the use of delimiters or warnings to ignore embedded instructions in these files.\n
- Capability inventory: The generated wizard script has the capability to write to the local filesystem (.env files) and interact with GitHub secrets via the gh CLI tool.\n
- Sanitization: None; there is no specified validation or filtering of content ingested from the repository before use in script generation.
Audit Metadata