ax
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill recommends and implements the installation of the 'ax' CLI tool via a shell script downloaded from 'https://ax.yusuke.run/install' and piped directly into the system shell.
- [PRIVILEGE_ESCALATION]: The setup script ('scripts/setup.sh') contains logic to move the downloaded binary into system directories like '/usr/local/bin' using 'sudo', which is a high-privilege operation standard for global software installation.
- [COMMAND_EXECUTION]: The skill includes Python, Node.js, and Bash wrappers that execute the 'ax' binary through shell commands to perform web discovery and data extraction tasks.
- [EXTERNAL_DOWNLOADS]: The skill downloads binaries and installation scripts from 'ax.yusuke.run' and 'github.com/yusukebe', which are the official project sites for the 'ax' tool.
- [INDIRECT_PROMPT_INJECTION]: The skill enables agents to fetch and process web content from arbitrary URLs, creating an attack surface where malicious data from external websites could attempt to influence the agent's behavior.
- Ingestion points: Web content is ingested whenever the 'ax' command is used to fetch a URL (e.g., in 'SKILL.md' and 'tools/ax_tool.py').
- Boundary markers: The tool supports token budgeting via the '--budget' flag and structural discovery using '--outline' to limit the amount of raw, potentially unsafe HTML returned to the agent.
- Capability inventory: The skill provides capability for project scaffolding (filesystem writes) and CLI execution (subprocess calls in wrappers).
- Sanitization: Employs a specific, restricted expression language for the '--where' filtering flag to prevent code injection within the tool's filtering logic.
Recommendations
- HIGH: Downloads and executes remote code from: https://ax.yusuke.run/install - DO NOT USE without thorough review
Audit Metadata