5dive-cli
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONPERSISTENCEEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The 5dive CLI supports the execution of user-defined shell commands for various orchestration tasks, including task verification (
--verify), environment access probing (--probe), and dynamic context gathering for scheduled motions (--context-cmd). These are core features for the runtime's automated workflows. - [PRIVILEGE_ESCALATION]: The skill documents administrative commands that manage agent isolation tiers (standard, admin, sandboxed). It also includes a capability to confer unrestricted root access to an agent via
5dive agent grant <name> root, which is an explicit and audited administrative action. - [INDIRECT_PROMPT_INJECTION]: The inter-agent messaging system (
agent send/agent ask) and the shared task queue provide an ingestion surface for untrusted data. The CLI includes mitigation strategies, such as wrapping messages in metadata headers ([5dive-msg from=...]) to help agents distinguish peer communication from user input. - [PERSISTENCE]: The runtime establishes durability for agents using
systemdunits andcronjobs for heartbeat monitoring and recurring task materialization. This behavior is documented as the intended mechanism for maintaining agent presence on the host. - [EXTERNAL_DOWNLOADS]: The tool facilitates the installation of external code through commands like
5dive crew install <git-url>and5dive plugin add <plugin>, which download and configure runtime components. These operations are part of the vendor-provided plugin and orchestration framework.
Audit Metadata