cli-proxy
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill documentation describes a proxy mechanism that routes API requests to various local command-line interfaces (CLIs) including claude, gemini, qwen, kilo, opencode, and a pi CLI. This pattern involves the dynamic invocation of local system binaries based on model aliases and effort levels provided in the network request.
- [COMMAND_EXECUTION]: The skill manages and interacts with local services through a systemd user unit (cli-proxy.service). The routing logic translates API calls into shell commands executed against third-party CLI tools.
- [INDIRECT_PROMPT_INJECTION]: The skill exposes a local network endpoint at http://127.0.0.1:7890/v1 which acts as a bridge between untrusted external data and internal system tools. \n
- Ingestion points: Network endpoint at 127.0.0.1:7890/v1 accepting chat completion payloads. \n
- Boundary markers: The skill explicitly instructs to fold system-role messages into user turns for specific providers, which modifies the structure of the input but provides no security boundaries. \n
- Capability inventory: The skill has the capability to execute multiple local binaries (CLIs) and perform external network operations to the MiniMax API. \n
- Sanitization: There is no evidence of input validation or sanitization for the messages being passed to the underlying CLI tools.
Audit Metadata