skills/yeachan-heo/oh-my-codex/ask/Gen Agent Trust Hub

ask

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute shell commands (e.g., claude -p "{{ARGUMENTS}}", gemini -p "{{ARGUMENTS}}", and omx ask ...) using the {{ARGUMENTS}} placeholder. This pattern is highly susceptible to shell command injection. A malicious user could provide arguments containing shell metacharacters (such as ;, |, &&, or backticks) to break out of the intended command and execute arbitrary code on the underlying host system.
  • [DYNAMIC_EXECUTION]: The skill utilizes dynamic string construction for shell execution. By instructing the agent to wrap user-provided input directly into a command-line string, it creates an insecure runtime execution environment where the boundary between data and code is not maintained.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 04:53 PM
Security Audit — agent-trust-hub — ask