agent-import
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: In
SKILL.md(Step 3f), the agent is instructed to interpret natural language descriptions from an importedtasks.jsonfile to write functionalrun.pyscripts, which are then executed via a shell command (bash("python3 tasks/{job_id}/run.py")). This creates a path for arbitrary code execution if the source description is maliciously crafted. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external migration bundle which could contain malicious instructions.
- Ingestion points:
SKILL.mdinstructions involve readingtasks.json,soul.md,agent.json, and other files extracted from the downloaded archive. - Boundary markers: No specific delimiters or "ignore instructions" guards are implemented when reading the contents of these files.
- Capability inventory: The agent has the ability to execute shell commands, perform file system operations (
cp), and update internal state (memory,agent_profile). - Sanitization: The instructions rely on the agent's manual review of the manifest and contents before application, but do not provide programmatic sanitization of the input.
- [COMMAND_EXECUTION]: The skill executes a local Python script
scripts/download.pyusing user-supplied arguments (CODEandDOWNLOAD_TOKEN). - [REMOTE_CODE_EXECUTION]: The skill downloads a compressed archive from a remote service (
sc-agent-migration.internal) and subsequently executes code or logic derived from the contents of that archive.
Audit Metadata