second-brain
Warn
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The script
scripts/ensue-api.shconstructs acurlcommand by interpolating the$ARGSand$METHODvariables directly into a double-quoted string. Because Bash evaluates subshells (e.g.,$(...)) and backticks within double quotes, this pattern is vulnerable to shell command injection if the input contains these metacharacters. - [INDIRECT_PROMPT_INJECTION]: The skill serves as a surface for indirect prompt injection by processing untrusted user content and passing it to the vulnerable shell script.
- Ingestion points: Captured user knowledge and search queries processed through
SKILL.md(e.g., via "save this" or "remember" commands). - Boundary markers: The skill includes instructions for the agent to "confirm before saving" and "show draft", providing a human-in-the-loop checkpoint.
- Capability inventory: The
scripts/ensue-api.shscript executes network requests viacurland processes output withsed. - Sanitization: The script performs no programmatic sanitization, shell escaping, or validation of the
$ARGSvariable before passing it to the shell for execution. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to
api.ensue-network.aito store and retrieve memories. This is the intended endpoint for the skill's primary functionality.
Audit Metadata