agentspace

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the @agentspace-so/ascli CLI tool from the official NPM registry using npm install or npx. This is a standard method for distributing and using vendor-provided utilities.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to install dependencies and execute the sharing utility (e.g., npm install -g, npx, ascli share). These operations are consistent with its primary purpose as a developer productivity tool.
  • [DATA_EXFILTRATION]: The skill's core function is to upload local files and folders to agentspace.so. The instructions include explicit guardrails requiring the agent to confirm the exact target path with the user to prevent the accidental exposure of sensitive directories or unauthorized data transmission.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes local data by ingesting files and folders for sharing, which represents a potential injection surface.
  • Ingestion points: User-specified files and directories provided through the <path> argument (SKILL.md, references/commands.md).
  • Boundary markers: The skill does not implement boundary markers for file content, though it requires explicit user confirmation of the target path before the upload capability is triggered.
  • Capability inventory: Includes shell command execution, package installation, and network communication with agentspace.so.
  • Sanitization: No sanitization of the shared file content is performed, as the tool acts as a transport mechanism.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 10:38 AM
Security Audit — agent-trust-hub — agentspace