openagent
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill includes a command
sudo 5dive agent importto provision new agents from persona files, which requires elevated system privileges. - [INDIRECT_PROMPT_INJECTION]: The skill authors identity files based on user-provided descriptions, creating a surface for indirect prompt injection.
- Ingestion points: User input gathered in the Workflow section of
SKILL.mdfor fields likename,behavior, andvoice.written.sample. - Boundary markers: Content is structured into a YAML file, but no explicit input delimiters are mentioned during the gathering phase.
- Capability inventory: Shell command execution via
npx, network operations viacurl, and privileged execution viasudoare all present inSKILL.md. - Sanitization: The skill performs schema validation using the
npx @5dive/openagent validatecommand to ensure the persona file is well-formed. - [COMMAND_EXECUTION]: The skill executes the vendor-provided
@5dive/openagentCLI tool usingnpxto perform validation, tiering, and card rendering tasks. - [EXTERNAL_DOWNLOADS]: The skill utilizes
curlto download portrait images frompollinations.aias a fallback generation method.
Audit Metadata