vm-lab
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill extensively uses the
prlctlutility to manage Parallels Virtual Machines. This includes host-level execution for listing VMs, capturing screenshots to the host's/tmpdirectory, and executing arbitrary shells or scripts within the guest OS viaprlctl exec. - [COMMAND_EXECUTION]: The
scripts/parallels_type.pyscript usessubprocess.runto callprlctl send-key-eventon the host. While the script usesrepr()(!r) formatting to mitigate host-side injection, the resulting string is interpreted by the guest shell, creating a potential command injection surface within the guest environment if the agent provides unsanitized application names. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and act upon data from the VM environment, including terminal output, JSON results from tools, and screenshots.
- Ingestion points: Terminal output from
prlctl exec, screenshot analysis viaprlctl captureandsips, and tool output from thePeekabooCLI in the guest. - Boundary markers: Absent. The instructions do not define delimiters for guest-provided data.
- Capability inventory: Host-side file writing (
/tmp/vm-reference.png), host-side command execution (prlctl), and full guest OS control. - Sanitization: Keystrokes are passed via JSON encoding. Guest command execution relies on string concatenation, which is a common vulnerability surface, though limited to the scope of the VM.
Audit Metadata