nasiko-control-plane
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions for the agent to install and execute external software binaries from a third-party GitHub repository.
- Evidence: SKILL.md specifies the installation of the Nasiko CLI from https://github.com/Nasiko-Labs/nasiko.
- Context: The risk is addressed by instructions requiring the agent to use a pinned version (v0.1.0), verify SHA-256 digests, and obtain explicit user consent after a dry-run.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local command outputs, which serves as a potential vector for indirect prompt injection if the tool output is manipulated.
- Ingestion points: The agent is instructed in SKILL.md to start by reading JSON output from the ecc nasiko status command.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat this external tool output as potentially untrusted data.
- Capability inventory: The skill allows the agent to execute installation and uninstallation commands (ecc nasiko install, ecc nasiko uninstall) which perform operations on the host system.
- Sanitization: There are no specific instructions for validating or sanitizing the content of the JSON output before the agent processes it.
- [COMMAND_EXECUTION]: The skill relies on shell command execution to perform lifecycle management of the CLI tool.
- Evidence: SKILL.md contains multiple shell command patterns such as ecc nasiko status, ecc nasiko install, and ecc nasiko uninstall.
Audit Metadata