select-models
Fail
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/validate.shscript executes model templates usingbash -c. Because this template is generated by the agent or provided by the user without sanitization, it allows for arbitrary shell command injection if metacharacters (such as semicolons, pipes, or backticks) are included in the template string.\n- [CREDENTIALS_UNSAFE]: Thescripts/discover.shscript probes for API keys in thepasspassword store (e.g.,pass show api/anthropic/api-key) and environment variables. Accessing a specialized credential management tool is a sensitive operation that exposes the presence of keys to the agent context.\n- [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of arbitrary remote code by allowing the agent to define and immediately run shell command templates. If these templates point to external binaries or include piped network operations, they will be executed during the validation phase.\n- [DATA_EXFILTRATION]: The discovery logic reveals the availability and status of various API keys (Anthropic, Minimax, OpenRouter, Chutes) to the agent. This mapping of the user's available services and account status can be used to identify targets for further data exfiltration.
Recommendations
- AI detected serious security threats
Audit Metadata