advpr-test-automation

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The FWTestHelper API includes methods UTAtzPsw and UTDelPsw that allow for the manipulation (updating or deleting) of the Protheus system password file (SIGAPSS.spf). Additionally, UTSetAuthorization is used to generate Base64-encoded credentials for API authentication.\n- [PRIVILEGE_ESCALATION]: The framework exposes numerous high-privilege operations for environment preparation, including UTUpdateDB and UTDeleteDB for direct SQL manipulation, UTClearDB for clearing tables, UTAtuSX3 for runtime schema changes, and UTUpdComp for altering table sharing configurations.\n- [DYNAMIC_EXECUTION]: The skill documents methods for executing dynamic logic, such as UTExecTelNet for running VBS scripts and UTCommitData or ExecStatic for executing arbitrary ADVPL code blocks and static functions.\n- [COMMAND_EXECUTION]: Documentation explains how to trigger headless test executions via the command line using appserver.exe -run=FwExecSuite.\n- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface for indirect prompt injection as it facilitates the ingestion of external data from CSV files, XML files, and API responses (SetCsv, SetXml, UTGetWS) which are then processed by a framework with broad system access and execution capabilities. The documentation does not specify sanitization or boundary markers for this external data.\n- [EXTERNAL_DOWNLOADS]: The skill references an external setup page on the official vendor domain (http://advpr.totvs.com.br:8080/#/setup) to download necessary patches for the framework.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 11:02 AM
Security Audit — agent-trust-hub — advpr-test-automation