agency-propose
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (
grep -li "[business name]" *.md) where the business name is a user-provided parameter. This allows for command injection if the input contains shell metacharacters, enabling arbitrary code execution on the host system.\n- [DATA_EXFILTRATION]: Through the command injection vulnerability, an attacker could access and exfiltrate sensitive files, credentials, or environment variables from the local environment using network-enabled tools.\n- [INDIRECT_PROMPT_INJECTION]: The skill scans and reads content from numerous external markdown files, presenting an attack surface for indirect prompt injection.\n - Ingestion points: Reads all files matching specific patterns (e.g.,
AGENCY-ONBOARD-*.md,MARKETING-AUDIT*.md) and any.mdfile containing the business name.\n - Boundary markers: The instructions do not define delimiters or provide warnings to the agent to ignore instructions embedded within the source files.\n
- Capability inventory: The agent has permissions to execute bash commands, read local files, and write new markdown files.\n
- Sanitization: There is no evidence of sanitization or validation of the ingested content before it is processed to generate the final proposal.
Recommendations
- AI detected serious security threats
Audit Metadata