nasiko-control-plane

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for the agent to install and execute external software binaries from a third-party GitHub repository.
  • Evidence: SKILL.md specifies the installation of the Nasiko CLI from https://github.com/Nasiko-Labs/nasiko.
  • Context: The risk is addressed by instructions requiring the agent to use a pinned version (v0.1.0), verify SHA-256 digests, and obtain explicit user consent after a dry-run.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local command outputs, which serves as a potential vector for indirect prompt injection if the tool output is manipulated.
  • Ingestion points: The agent is instructed in SKILL.md to start by reading JSON output from the ecc nasiko status command.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to treat this external tool output as potentially untrusted data.
  • Capability inventory: The skill allows the agent to execute installation and uninstallation commands (ecc nasiko install, ecc nasiko uninstall) which perform operations on the host system.
  • Sanitization: There are no specific instructions for validating or sanitizing the content of the JSON output before the agent processes it.
  • [COMMAND_EXECUTION]: The skill relies on shell command execution to perform lifecycle management of the CLI tool.
  • Evidence: SKILL.md contains multiple shell command patterns such as ecc nasiko status, ecc nasiko install, and ecc nasiko uninstall.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 08:29 AM
Security Audit — agent-trust-hub — nasiko-control-plane