fix-security-vulnerabilities-with-strix

Warn

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple sources which could contain malicious instructions designed to influence the agent's behavior during the remediation process.
  • Ingestion points: Processes finding details, descriptions, and remediation guidance from local files (vulnerabilities/*.md, vulnerabilities.json, findings.sarif) and the Strix Cloud API (app.strix.ai/api/v1/vulnerabilities).
  • Boundary markers: None identified. The instructions do not specify using delimiters or warnings to ignore embedded instructions in the findings data.
  • Capability inventory: The skill has the capability to modify repository source code, execute the strix CLI, perform network operations via curl, and execute arbitrary shell commands (PoC scripts).
  • Sanitization: No evidence of sanitization or validation of the content within the finding files before execution or interpretation.
  • [DYNAMIC_EXECUTION]: The instructions explicitly direct the agent to execute code provided in data files to reproduce and verify vulnerabilities.
  • Evidence: The skill states: "Reproduce it with the PoC from the finding file when feasible" and "re-run the PoC manually when it is a simple request/script". This involves executing scripts or commands defined in the poc_script_code or finding descriptions.
  • [COMMAND_EXECUTION]: The skill uses shell commands for project environment setup and verification.
  • Evidence: Uses git to determine diff bases and strix CLI to perform security scans. It also uses curl to interact with the vendor's cloud API for re-running scans and polling results.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 2, 2026, 09:12 PM
Security Audit — agent-trust-hub — fix-security-vulnerabilities-with-strix