5dive-cli-extras
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFEPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates broad system command execution through
sudo 5dive hostfor unit remediation, journal access, and cron management. - [REMOTE_CODE_EXECUTION]: The skill supports downloading and installing code from external sources, including GitHub repositories and arbitrary Git URLs via
5dive plugin add <owner>/<repo>and5dive crew install <git-url>. - [DYNAMIC_EXECUTION]: The
agent importcommand allows for the execution of 'hooks', described as arbitrary shell scripts that run automatically on agent tool events. - [PRIVILEGE_ESCALATION]: Extensive use of
sudofor management tasks, such assudo 5dive agent create,sudo 5dive account login, andsudo 5dive plugin add, providing a mechanism for agents to perform operations with root permissions. - [CREDENTIALS_UNSAFE]: The skill manages sensitive authentication material, including API keys for various LLM providers (e.g., Anthropic, OpenAI, DeepSeek), SSH keys via
5dive fleet add, and mints temporary GitHub tokens for repository operations. - [PERSISTENCE]: The skill can establish persistence through
task add --recurringfor scheduled tasks and5dive proof on, which installs a daily root cron job. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external messaging channels (Telegram, Discord) and GitHub/webhook triggers, which are then passed to agents via
5dive agent sendwithout explicit sanitization. 1. Ingestion points: Telegram/Discord messages, GitHub issue labels, and Webhook deliveries. 2. Boundary markers: None specified in instructions. 3. Capability inventory: Root command execution, file writing (wiki, secrets), and network operations (GitHub push, fleet SSH). 4. Sanitization: No evidence of filtering or escaping external content before redirection.
Audit Metadata