geo-brand-mentions

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill executes an inline Python script via python3 -c where the placeholder [Brand_Name] is directly interpolated into a string literal (brand = '[Brand_Name]'). This represents runtime script generation and dynamic execution from string templates.
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes a vulnerability surface through untrusted data ingestion combined with high capabilities:
  • Ingestion points: The brand name and related metrics are gathered from the user or from external websites via WebFetch as specified in Step 1.
  • Boundary markers: There are no boundary markers, escaping mechanisms, or constraints defined to isolate the untrusted placeholder from the execution payload.
  • Capability inventory: The skill utilizes the Bash tool to run command-line actions and execute local python code.
  • Sanitization: No validation or sanitization is applied to [Brand_Name]. If a retrieved brand name contains single quotes or command termination sequences (e.g., '; import os; os.system(...) #), it will escape the Python string literal and result in arbitrary command execution.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 09:50 PM
Security Audit — agent-trust-hub — geo-brand-mentions