second-brain

Warn

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/ensue-api.sh constructs a curl command by interpolating the $ARGS and $METHOD variables directly into a double-quoted string. Because Bash evaluates subshells (e.g., $(...)) and backticks within double quotes, this pattern is vulnerable to shell command injection if the input contains these metacharacters.
  • [INDIRECT_PROMPT_INJECTION]: The skill serves as a surface for indirect prompt injection by processing untrusted user content and passing it to the vulnerable shell script.
  • Ingestion points: Captured user knowledge and search queries processed through SKILL.md (e.g., via "save this" or "remember" commands).
  • Boundary markers: The skill includes instructions for the agent to "confirm before saving" and "show draft", providing a human-in-the-loop checkpoint.
  • Capability inventory: The scripts/ensue-api.sh script executes network requests via curl and processes output with sed.
  • Sanitization: The script performs no programmatic sanitization, shell escaping, or validation of the $ARGS variable before passing it to the shell for execution.
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to api.ensue-network.ai to store and retrieve memories. This is the intended endpoint for the skill's primary functionality.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 21, 2026, 02:04 PM
Security Audit — agent-trust-hub — second-brain