byo-proxy
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill facilitates the management of residential proxy configurations and credentials. It provides a structured API in
exports.pyand CLI scripts for setup, binding, and verification. - [SAFE]: Proxy credentials (usernames and passwords) are persisted in the workspace
.envfile, following the platform's recommended practices for secret management. - [SAFE]: Network activity is restricted to verifying proxy connectivity via the well-known
ifconfig.coservice. No sensitive data or telemetry is exfiltrated to unauthorized domains. - [INDIRECT_PROMPT_INJECTION]: The skill provides an API that generates remediation instructions containing shell commands built from untrusted inputs.
- Ingestion points: The
skill_nameparameter in theget_proxy_for_skillandonboarding_guidefunctions withinexports.py. - Boundary markers: No delimiters or escape sequences are applied to the skill name before it is included in the suggested command string.
- Capability inventory: The skill possesses capabilities for filesystem access (reading/writing
.envand.jsonfiles) and network operations (proxy-aware requests). - Sanitization: The
skill_nameis interpolated directly into a suggested shell command string without validation or shell-escaping. If an automated agent attempts to execute these suggested remediation steps verbatim, a maliciously crafted skill name could result in command injection.
Audit Metadata