cli-anything
Fail
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
cli-anything-hubPython package from a public registry and retrieves agent skills from the HKUDS repository on GitHub usingnpx. These are expected components for the skill's stated functionality. - [REMOTE_CODE_EXECUTION]: A
curl | shexecution pattern was detected inscripts/install.sh. However, this pattern is contained within anechocommand intended to provide the user with manual installation steps for theuvpackage manager and is not executed by the script itself. - [COMMAND_EXECUTION]: The skill and its installer script execute several shell commands, including
pip install,npx skills add, andcli-huboperations, to manage the installation and execution of CLI harnesses. It also invokespytestto validate generated code. - [PROMPT_INJECTION]: The skill functions by ingesting external source code or repositories, which creates a surface for indirect prompt injection where malicious instructions could be hidden in the analyzed data.
- Ingestion points: Local directories and remote GitHub repositories provided via the
/cli-anythingcommand inSKILL.md. - Boundary markers: None identified; the skill processes the full content of the target codebase without explicit delimiters to ignore embedded instructions.
- Capability inventory: Capability to write files to the local system, install packages (
pip install -e .), and execute shell commands or tests. - Sanitization: No documented sanitization or filtering of input source code to prevent the interpretation of embedded natural language instructions by the agent.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
Audit Metadata