fix-security-vulnerabilities-with-strix
Warn
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which could contain malicious instructions designed to influence the agent's behavior during the remediation process.
- Ingestion points: Processes finding details, descriptions, and remediation guidance from local files (
vulnerabilities/*.md,vulnerabilities.json,findings.sarif) and the Strix Cloud API (app.strix.ai/api/v1/vulnerabilities). - Boundary markers: None identified. The instructions do not specify using delimiters or warnings to ignore embedded instructions in the findings data.
- Capability inventory: The skill has the capability to modify repository source code, execute the
strixCLI, perform network operations viacurl, and execute arbitrary shell commands (PoC scripts). - Sanitization: No evidence of sanitization or validation of the content within the finding files before execution or interpretation.
- [DYNAMIC_EXECUTION]: The instructions explicitly direct the agent to execute code provided in data files to reproduce and verify vulnerabilities.
- Evidence: The skill states: "Reproduce it with the PoC from the finding file when feasible" and "re-run the PoC manually when it is a simple request/script". This involves executing scripts or commands defined in the
poc_script_codeor finding descriptions. - [COMMAND_EXECUTION]: The skill uses shell commands for project environment setup and verification.
- Evidence: Uses
gitto determine diff bases andstrixCLI to perform security scans. It also usescurlto interact with the vendor's cloud API for re-running scans and polling results.
Audit Metadata