dse-loop
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill instructions require the agent to generate and execute custom scripts (e.g.,
dse_results/parse_result.py) at runtime to extract metrics from program outputs. This dynamic generation and execution of code based on analyzed project data is a medium-risk pattern. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources which could contain malicious instructions designed to influence the agent's autonomous loop.
- Ingestion points: Program stdout, log files, project source code (searched for parameter definitions), and generated reports in
dse_results/. - Boundary markers: None identified. The instructions do not specify the use of delimiters or warnings to ignore instructions embedded in the data being parsed.
- Capability inventory: The skill has broad capabilities including
Bash(*),Write, andEdit, allowing it to modify the environment or exfiltrate data if manipulated. - Sanitization: There are no explicit instructions for sanitizing or validating the content parsed from external outputs before using it to decide the next iteration's parameters.
- [COMMAND_EXECUTION]: The core functionality of the skill relies on executing arbitrary shell commands and build tools (e.g.,
make,gcc,simulators) provided in the user arguments, which could be exploited if the user input is not carefully constrained.
Audit Metadata