rspack-sftrace
Warn
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to clone the
sftracerepository from an external GitHub account (github.com/quininer/sftrace) which is not recognized as a trusted organization or well-known service. - [REMOTE_CODE_EXECUTION]: The workflow involves downloading source code from an external repository and subsequently executing it after a compilation step. This pattern constitutes remote code execution from an unverified source.
- [DYNAMIC_EXECUTION]: The instructions require the agent to compile the downloaded source code at runtime using
cargo build --releasebefore the resulting binary is used for profiling tasks. - [COMMAND_EXECUTION]: The skill executes multiple shell commands to manage the profiling lifecycle, including
git clone,cargo,pnpm, and the customsftracebinary. It uses command substitution and wraps other processes (e.g.,sftrace record -- pnpm build) to capture performance data. - [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by ingesting and analyzing data from the user's project environment.
- Ingestion points: Reads function symbols from compiled binary
.nodefiles and processes event logs from generated Parquet files (sf.pola,sf.pola.symtab). - Boundary markers: There are no explicit markers or instructions guiding the agent to treat the demangled symbol names or file paths as untrusted content.
- Capability inventory: The agent has capabilities for filesystem modification (
mkdir,cp, file writes), network access (git clone), and subprocess execution (cargo,pnpm,sftrace). - Sanitization: No evidence of sanitization or validation of the ingested function symbols or path metadata is present in the analysis scripts or command-line workflows.
Audit Metadata