byo-proxy

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill facilitates the management of residential proxy configurations and credentials. It provides a structured API in exports.py and CLI scripts for setup, binding, and verification.
  • [SAFE]: Proxy credentials (usernames and passwords) are persisted in the workspace .env file, following the platform's recommended practices for secret management.
  • [SAFE]: Network activity is restricted to verifying proxy connectivity via the well-known ifconfig.co service. No sensitive data or telemetry is exfiltrated to unauthorized domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides an API that generates remediation instructions containing shell commands built from untrusted inputs.
  • Ingestion points: The skill_name parameter in the get_proxy_for_skill and onboarding_guide functions within exports.py.
  • Boundary markers: No delimiters or escape sequences are applied to the skill name before it is included in the suggested command string.
  • Capability inventory: The skill possesses capabilities for filesystem access (reading/writing .env and .json files) and network operations (proxy-aware requests).
  • Sanitization: The skill_name is interpolated directly into a suggested shell command string without validation or shell-escaping. If an automated agent attempts to execute these suggested remediation steps verbatim, a maliciously crafted skill name could result in command injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:24 AM
Security Audit — agent-trust-hub — byo-proxy