skills/akillness/jeo-skills/ax/Gen Agent Trust Hub

ax

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill recommends and implements the installation of the 'ax' CLI tool via a shell script downloaded from 'https://ax.yusuke.run/install' and piped directly into the system shell.
  • [PRIVILEGE_ESCALATION]: The setup script ('scripts/setup.sh') contains logic to move the downloaded binary into system directories like '/usr/local/bin' using 'sudo', which is a high-privilege operation standard for global software installation.
  • [COMMAND_EXECUTION]: The skill includes Python, Node.js, and Bash wrappers that execute the 'ax' binary through shell commands to perform web discovery and data extraction tasks.
  • [EXTERNAL_DOWNLOADS]: The skill downloads binaries and installation scripts from 'ax.yusuke.run' and 'github.com/yusukebe', which are the official project sites for the 'ax' tool.
  • [INDIRECT_PROMPT_INJECTION]: The skill enables agents to fetch and process web content from arbitrary URLs, creating an attack surface where malicious data from external websites could attempt to influence the agent's behavior.
  • Ingestion points: Web content is ingested whenever the 'ax' command is used to fetch a URL (e.g., in 'SKILL.md' and 'tools/ax_tool.py').
  • Boundary markers: The tool supports token budgeting via the '--budget' flag and structural discovery using '--outline' to limit the amount of raw, potentially unsafe HTML returned to the agent.
  • Capability inventory: The skill provides capability for project scaffolding (filesystem writes) and CLI execution (subprocess calls in wrappers).
  • Sanitization: Employs a specific, restricted expression language for the '--where' filtering flag to prevent code injection within the tool's filtering logic.
Recommendations
  • HIGH: Downloads and executes remote code from: https://ax.yusuke.run/install - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 06:01 PM
Security Audit — agent-trust-hub — ax