can
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes system-level commands to discover available CAN hardware interfaces.
- Evidence:
scripts/can_runtime.pyandscripts/can_scan.pyusesubprocess.runto callpowershell,lsusb, andipfor enumerating USB devices and network interfaces. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources (CAN bus traffic and log files), presenting a surface for indirect prompt injection.
- Ingestion points: Data is ingested from live CAN interfaces in
can_monitor.py,can_log.py, andcan_stats.py, and from external files incan_decode.py. - Boundary markers: No explicit boundary markers or safety instructions are used when displaying the content of CAN messages to the agent.
- Capability inventory: The skill has the ability to write to the CAN bus using
python-can, write files to the local system (logs), and execute system discovery commands. - Sanitization: CAN data is treated as hex strings or raw bytes, which minimizes but does not eliminate the risk of the LLM interpreting data as instructions.
Audit Metadata