skills/steipete/agent-scripts/vm-lab/Gen Agent Trust Hub

vm-lab

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill extensively uses the prlctl utility to manage Parallels Virtual Machines. This includes host-level execution for listing VMs, capturing screenshots to the host's /tmp directory, and executing arbitrary shells or scripts within the guest OS via prlctl exec.
  • [COMMAND_EXECUTION]: The scripts/parallels_type.py script uses subprocess.run to call prlctl send-key-event on the host. While the script uses repr() (!r) formatting to mitigate host-side injection, the resulting string is interpreted by the guest shell, creating a potential command injection surface within the guest environment if the agent provides unsanitized application names.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from the VM environment, including terminal output, JSON results from tools, and screenshots.
  • Ingestion points: Terminal output from prlctl exec, screenshot analysis via prlctl capture and sips, and tool output from the Peekaboo CLI in the guest.
  • Boundary markers: Absent. The instructions do not define delimiters for guest-provided data.
  • Capability inventory: Host-side file writing (/tmp/vm-reference.png), host-side command execution (prlctl), and full guest OS control.
  • Sanitization: Keystrokes are passed via JSON encoding. Guest command execution relies on string concatenation, which is a common vulnerability surface, though limited to the scope of the VM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 11:28 PM
Security Audit — agent-trust-hub — vm-lab