paper-illustration

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The optional style reference section details a shell script workflow where the user-provided <source> input is directly interpolated into a command line string: python3 "$STYLE_HELPER" --source "<source>". If the agent platform performs literal string substitution without filtering or escaping quotes and shell metacharacters, this pattern presents a command injection vulnerability.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection attack surface by accepting external reference documents.
  • Ingestion points: External data enters the agent environment via the --style-ref parameter within $ARGUMENTS, which accepts remote HTTP/HTTPS URLs, local files, and arXiv IDs.
  • Boundary markers: Absent. The instructions lack strict isolation guidelines or explicit system prompt directives telling the model to disregard natural language commands contained inside the fetched style profiles.
  • Capability inventory: The skill possesses extensive capabilities including file system writes to figures/ai_generated/, network interactions via curl, and arbitrary shell execution through the Bash tool.
  • Sanitization: Absent. No text normalization, filtering, or instruction-stripping steps are declared before the external reference is consumed as structural guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — paper-illustration