geo-brand-mentions
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill executes an inline Python script via
python3 -cwhere the placeholder[Brand_Name]is directly interpolated into a string literal (brand = '[Brand_Name]'). This represents runtime script generation and dynamic execution from string templates. - [INDIRECT_PROMPT_INJECTION]: The skill exposes a vulnerability surface through untrusted data ingestion combined with high capabilities:
- Ingestion points: The brand name and related metrics are gathered from the user or from external websites via
WebFetchas specified in Step 1. - Boundary markers: There are no boundary markers, escaping mechanisms, or constraints defined to isolate the untrusted placeholder from the execution payload.
- Capability inventory: The skill utilizes the
Bashtool to run command-line actions and execute local python code. - Sanitization: No validation or sanitization is applied to
[Brand_Name]. If a retrieved brand name contains single quotes or command termination sequences (e.g.,'; import os; os.system(...) #), it will escape the Python string literal and result in arbitrary command execution.
Audit Metadata