xdrop
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill downloads and processes file manifests from external Xdrop servers. An attacker-controlled server could serve malicious metadata intended to influence the agent's logic.\n
- Ingestion points: The
scripts/download.mjsscript fetches transfer descriptors and manifest files from remote URLs.\n - Boundary markers: The skill does not use explicit delimiters when reporting file paths or transfer statuses back to the agent.\n
- Capability inventory: The scripts are capable of writing to the local filesystem and performing network requests.\n
- Sanitization: A
sanitizePathfunction is implemented inscripts/download.mjsto filter path traversal sequences like '..' and strip illegal OS-specific characters.\n- [EXTERNAL_DOWNLOADS]: The tool performs network communication with user-provided Xdrop server URLs to transfer binary data and encrypted manifests.\n- [COMMAND_EXECUTION]: The skill requires the agent to execute bundled JavaScript scripts using the Bun runtime to perform its file and network tasks.
Audit Metadata