coverage
Warn
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill includes command patterns in SKILL.md that use 'sudo' with package managers like 'apt-get' and 'yum' to install development headers and compilers ('gcc', 'python-dev'), which involves acquiring elevated system permissions.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill provides patterns for installing the 'coverage' package from the official PyPI registry using pip.
- [INDIRECT_PROMPT_INJECTION]: The skill processes documentation from external reference files, creating a potential attack surface. Ingestion points: 'references/7.13.4.md'; Boundary markers: Absent; Capability inventory: Shell command execution ('coverage', 'sudo', 'pip'); Sanitization: Absent.
Audit Metadata