training-check
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is instructed to execute arbitrary shell commands provided in the session context, including a
stop_commandand user-defined log-reading commands (local or SSH). It is also authorized to choose and execute stop actions such as killing processes, tmux sessions, or remote jobs. This behavior creates a vector for arbitrary command execution if the context is sourced from or influenced by untrusted data. - [INDIRECT_PROMPT_INJECTION]: The skill implements an automated decision-making loop (CONTINUE/STOP) that relies on parsing external and potentially untrusted log files or WandB metrics. This creates a vulnerability surface where malicious content embedded in logs could manipulate the agent's decision logic.
- Ingestion points: The skill reads from fallback log files and WandB URLs identified during the setup phase.
- Boundary markers: Absent. There are no instructions for the agent to distinguish between legitimate log data and potentially malicious instructions within those logs.
- Capability inventory: The skill utilizes the
Bash(*)tool to perform system-level actions based on its analysis of the logs. - Sanitization: Absent. The skill analyzes raw log snippets directly to justify its decision to continue or stop training.
Audit Metadata