training-check

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is instructed to execute arbitrary shell commands provided in the session context, including a stop_command and user-defined log-reading commands (local or SSH). It is also authorized to choose and execute stop actions such as killing processes, tmux sessions, or remote jobs. This behavior creates a vector for arbitrary command execution if the context is sourced from or influenced by untrusted data.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an automated decision-making loop (CONTINUE/STOP) that relies on parsing external and potentially untrusted log files or WandB metrics. This creates a vulnerability surface where malicious content embedded in logs could manipulate the agent's decision logic.
  • Ingestion points: The skill reads from fallback log files and WandB URLs identified during the setup phase.
  • Boundary markers: Absent. There are no instructions for the agent to distinguish between legitimate log data and potentially malicious instructions within those logs.
  • Capability inventory: The skill utilizes the Bash(*) tool to perform system-level actions based on its analysis of the logs.
  • Sanitization: Absent. The skill analyzes raw log snippets directly to justify its decision to continue or stop training.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — training-check