skills/zhinkgit/embeddedskills/can/Gen Agent Trust Hub

can

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes system-level commands to discover available CAN hardware interfaces.
  • Evidence: scripts/can_runtime.py and scripts/can_scan.py use subprocess.run to call powershell, lsusb, and ip for enumerating USB devices and network interfaces.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources (CAN bus traffic and log files), presenting a surface for indirect prompt injection.
  • Ingestion points: Data is ingested from live CAN interfaces in can_monitor.py, can_log.py, and can_stats.py, and from external files in can_decode.py.
  • Boundary markers: No explicit boundary markers or safety instructions are used when displaying the content of CAN messages to the agent.
  • Capability inventory: The skill has the ability to write to the CAN bus using python-can, write files to the local system (logs), and execute system discovery commands.
  • Sanitization: CAN data is treated as hex strings or raw bytes, which minimizes but does not eliminate the risk of the LLM interpreting data as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:15 AM
Security Audit — agent-trust-hub — can