curl

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The installation scripts (scripts/install.sh and scripts/install.ps1) utilize standard package managers and require appropriate privileges for system-level installation of the curl utility.\n- [PROMPT_INJECTION]: The skill facilitates the retrieval of untrusted data from external URLs, which serves as a potential surface for indirect prompt injection if the agent processes the fetched content as instructions.\n
  • Ingestion points: Data retrieved via curl from external endpoints.\n
  • Boundary markers: Not present in the provided documentation or examples.\n
  • Capability inventory: Network access and file system writes via the curl tool.\n
  • Sanitization: No explicit sanitization of fetched content is performed by the skill itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 04:18 PM
Security Audit — agent-trust-hub — curl