skills/syn54x/skills-plus-plus/triage/Gen Agent Trust Hub

triage

Fail

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to perform verification by executing code from untrusted sources. Specifically, it directs the agent to "reproduce [a bug] from the reporter's steps" and, for Pull Requests (PRs), to "confirm the diff does what it claims: check it out, run the relevant tests or commands." This allows an attacker to achieve arbitrary code execution on the agent's host system by embedding malicious instructions or scripts in an issue report or pull request diff.
  • [COMMAND_EXECUTION]: The skill mandates the use of shell commands to verify external contributions without providing a restricted environment or security constraints for these commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it processes untrusted data from an external issue tracker.
  • Ingestion points: Reads the full body, comments, and diffs of issues and pull requests (SKILL.md, "Gather context").
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the processing logic.
  • Capability inventory: The skill has capabilities to execute shell commands ("run tests or commands") and write files to the codebase (".out-of-scope/" directory).
  • Sanitization: There is no evidence of sanitization or validation of the content retrieved from the issue tracker before it influences the agent's actions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — triage