select-models

Fail

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: HIGHCOMMAND_EXECUTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/validate.sh script executes model templates using bash -c. Because this template is generated by the agent or provided by the user without sanitization, it allows for arbitrary shell command injection if metacharacters (such as semicolons, pipes, or backticks) are included in the template string.\n- [CREDENTIALS_UNSAFE]: The scripts/discover.sh script probes for API keys in the pass password store (e.g., pass show api/anthropic/api-key) and environment variables. Accessing a specialized credential management tool is a sensitive operation that exposes the presence of keys to the agent context.\n- [REMOTE_CODE_EXECUTION]: The skill facilitates the execution of arbitrary remote code by allowing the agent to define and immediately run shell command templates. If these templates point to external binaries or include piped network operations, they will be executed during the validation phase.\n- [DATA_EXFILTRATION]: The discovery logic reveals the availability and status of various API keys (Anthropic, Minimax, OpenRouter, Chutes) to the agent. This mapping of the user's available services and account status can be used to identify targets for further data exfiltration.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 20, 2026, 08:53 PM
Security Audit — agent-trust-hub — select-models