cli-anything

Fail

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the cli-anything-hub Python package from a public registry and retrieves agent skills from the HKUDS repository on GitHub using npx. These are expected components for the skill's stated functionality.
  • [REMOTE_CODE_EXECUTION]: A curl | sh execution pattern was detected in scripts/install.sh. However, this pattern is contained within an echo command intended to provide the user with manual installation steps for the uv package manager and is not executed by the script itself.
  • [COMMAND_EXECUTION]: The skill and its installer script execute several shell commands, including pip install, npx skills add, and cli-hub operations, to manage the installation and execution of CLI harnesses. It also invokes pytest to validate generated code.
  • [PROMPT_INJECTION]: The skill functions by ingesting external source code or repositories, which creates a surface for indirect prompt injection where malicious instructions could be hidden in the analyzed data.
  • Ingestion points: Local directories and remote GitHub repositories provided via the /cli-anything command in SKILL.md.
  • Boundary markers: None identified; the skill processes the full content of the target codebase without explicit delimiters to ignore embedded instructions.
  • Capability inventory: Capability to write files to the local system, install packages (pip install -e .), and execute shell commands or tests.
  • Sanitization: No documented sanitization or filtering of input source code to prevent the interpretation of embedded natural language instructions by the agent.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 27, 2026, 11:38 AM
Security Audit — agent-trust-hub — cli-anything