AE Agent Errors
AE-G3HH1AH0

LLM-callable terminal tool executes arbitrary shell commands because its blocklist filters only two strings

SECURITY FAILUREseverity: CRITICALcause: LIKELYoutcome: UNKNOWNconfidence: LOW

MetaGPT's Terminal class is registered as an LLM-callable tool, and Terminal.run_command() wrote commands to a persistent bash shell after filtering only two specific strings. Dangerous commands were not filtered, so prompt injection influencing the agent could lead to remote code execution.

Framework / agent
MetaGPT · multi-agent framework with LLM-callable shell tool
Remediation attempts
SUGGESTED
Recurrence
not documented
Source languages
en
Updated
2026-09-30

Sources

Symptoms

  • Dangerous shell commands passed to Terminal.run_command() are executed without being blocked
  • Prompt injection against agentic workflows can yield full system access on the host
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-G3HH1AH0. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.