skills/5dive-ai/skills/openagent/Gen Agent Trust Hub

openagent

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill includes a command sudo 5dive agent import to provision new agents from persona files, which requires elevated system privileges.
  • [INDIRECT_PROMPT_INJECTION]: The skill authors identity files based on user-provided descriptions, creating a surface for indirect prompt injection.
  • Ingestion points: User input gathered in the Workflow section of SKILL.md for fields like name, behavior, and voice.written.sample.
  • Boundary markers: Content is structured into a YAML file, but no explicit input delimiters are mentioned during the gathering phase.
  • Capability inventory: Shell command execution via npx, network operations via curl, and privileged execution via sudo are all present in SKILL.md.
  • Sanitization: The skill performs schema validation using the npx @5dive/openagent validate command to ensure the persona file is well-formed.
  • [COMMAND_EXECUTION]: The skill executes the vendor-provided @5dive/openagent CLI tool using npx to perform validation, tiering, and card rendering tasks.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes curl to download portrait images from pollinations.ai as a fallback generation method.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 03:34 PM
Security Audit — agent-trust-hub — openagent