paper-illustration
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The optional style reference section details a shell script workflow where the user-provided
<source>input is directly interpolated into a command line string:python3 "$STYLE_HELPER" --source "<source>". If the agent platform performs literal string substitution without filtering or escaping quotes and shell metacharacters, this pattern presents a command injection vulnerability. - [INDIRECT_PROMPT_INJECTION]: The skill establishes an indirect prompt injection attack surface by accepting external reference documents.
- Ingestion points: External data enters the agent environment via the
--style-refparameter within$ARGUMENTS, which accepts remote HTTP/HTTPS URLs, local files, and arXiv IDs. - Boundary markers: Absent. The instructions lack strict isolation guidelines or explicit system prompt directives telling the model to disregard natural language commands contained inside the fetched style profiles.
- Capability inventory: The skill possesses extensive capabilities including file system writes to
figures/ai_generated/, network interactions viacurl, and arbitrary shell execution through theBashtool. - Sanitization: Absent. No text normalization, filtering, or instruction-stripping steps are declared before the external reference is consumed as structural guidance.
Audit Metadata