solai-knowledge
Warn
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions direct the agent to automatically execute a system command (
claude plugin update ctxl@contextual-io) upon its first invocation in a session. This command triggers the download and installation of external code, which is a significant execution vector for potential supply chain attacks. - [EXTERNAL_DOWNLOADS]: The skill relies on and manages the update lifecycle for a third-party plugin (
ctxl@contextual-io). The source for this plugin is not a verified trusted vendor or a well-known service, meaning its integrity and safety cannot be guaranteed.
Audit Metadata