agent-import

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: In SKILL.md (Step 3f), the agent is instructed to interpret natural language descriptions from an imported tasks.json file to write functional run.py scripts, which are then executed via a shell command (bash("python3 tasks/{job_id}/run.py")). This creates a path for arbitrary code execution if the source description is maliciously crafted.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from an external migration bundle which could contain malicious instructions.
  • Ingestion points: SKILL.md instructions involve reading tasks.json, soul.md, agent.json, and other files extracted from the downloaded archive.
  • Boundary markers: No specific delimiters or "ignore instructions" guards are implemented when reading the contents of these files.
  • Capability inventory: The agent has the ability to execute shell commands, perform file system operations (cp), and update internal state (memory, agent_profile).
  • Sanitization: The instructions rely on the agent's manual review of the manifest and contents before application, but do not provide programmatic sanitization of the input.
  • [COMMAND_EXECUTION]: The skill executes a local Python script scripts/download.py using user-supplied arguments (CODE and DOWNLOAD_TOKEN).
  • [REMOTE_CODE_EXECUTION]: The skill downloads a compressed archive from a remote service (sc-agent-migration.internal) and subsequently executes code or logic derived from the contents of that archive.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — agent-import