renoise-setup
Fail
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches manifest files, checksums, and binary archives from external sources, including the vendor's domain (download.renoise.ai) and a public GitHub repository (ArcoCodes/renoise-plugins-official).
- [REMOTE_CODE_EXECUTION]: The skill executes native binaries downloaded from the internet. The
scripts/install-cli.mjsscript extracts these binaries and runs them usingexecFileSyncto verify their functionality. TheSKILL.mdinstructions specify that the--ensureflag allows for these installations to be performed without explicit user prompts in certain automated workflows. - [COMMAND_EXECUTION]: The skill executes various system commands and provides instructions for the user to run others. It uses
execFileSyncto runtar,node,powershell.exe, and the downloadedrenoisebinary. It also suggests installation commands usingbrew,apt, andwingetfor system dependencies. - [DYNAMIC_EXECUTION]: The installation process involves dynamic platform detection and runtime execution of downloaded code. The script
install-cli.mjsdetermines the host OS and architecture at runtime to select the appropriate binary for download and execution. - [PRIVILEGE_ESCALATION]: The skill includes instructions that involve elevated permissions. It suggests using
sudo apt installfor dependencies on Debian-based systems. The installation script also useschmodSyncto modify file permissions, ensuring the downloaded binary is executable. - [INDIRECT_PROMPT_INJECTION]: The skill processes structured data from an external source which influences its execution flow. The script
scripts/install-cli.mjsingests a JSON manifest from a remote server. While the script includes validation for schema versions and uses regex for asset names, the data retrieved determines which binary is downloaded and executed.
Recommendations
- AI detected serious security threats
Audit Metadata