skills/apollographql/skills/rover/Gen Agent Trust Hub

rover

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides commands to fetch installation scripts from https://rover.apollo.dev/nix/latest and https://rover.apollo.dev/win/latest. These are official distribution endpoints for the Apollo Rover toolset.
  • [REMOTE_CODE_EXECUTION]: The provided installation workflow uses shell piping to execute remote content (curl | sh and iwr | iex). This is a high-capability pattern, though documented here for legitimate software setup.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by fetching and analyzing GraphQL schemas from external sources, creating a surface for indirect prompt injection attacks.
  • Ingestion points: External data enters the agent context via rover graph fetch, rover graph introspect, and rover subgraph introspect (SKILL.md, references/graphs.md, references/subgraphs.md).
  • Boundary markers: No specific delimiters or instructions are provided to the agent to treat external schema SDL as untrusted content.
  • Capability inventory: The skill is configured to use the Bash tool for running CLI commands and has permissions for reading and writing files (SKILL.md).
  • Sanitization: The skill lacks validation or sanitization mechanisms to filter malicious instructions potentially embedded in GraphQL schema comments or metadata.
Recommendations
  • HIGH: Downloads and executes remote code from: https://rover.apollo.dev/nix/latest - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 02:52 PM
Security Audit — agent-trust-hub — rover