agency-propose

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (grep -li "[business name]" *.md) where the business name is a user-provided parameter. This allows for command injection if the input contains shell metacharacters, enabling arbitrary code execution on the host system.\n- [DATA_EXFILTRATION]: Through the command injection vulnerability, an attacker could access and exfiltrate sensitive files, credentials, or environment variables from the local environment using network-enabled tools.\n- [INDIRECT_PROMPT_INJECTION]: The skill scans and reads content from numerous external markdown files, presenting an attack surface for indirect prompt injection.\n
  • Ingestion points: Reads all files matching specific patterns (e.g., AGENCY-ONBOARD-*.md, MARKETING-AUDIT*.md) and any .md file containing the business name.\n
  • Boundary markers: The instructions do not define delimiters or provide warnings to the agent to ignore instructions embedded within the source files.\n
  • Capability inventory: The agent has permissions to execute bash commands, read local files, and write new markdown files.\n
  • Sanitization: There is no evidence of sanitization or validation of the ingested content before it is processed to generate the final proposal.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 07:11 AM
Security Audit — agent-trust-hub — agency-propose