cpanel-toolkit

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes data from external sources, specifically cPanel error logs and API responses, creating a surface for indirect prompt injection. A malicious entity could potentially inject instructions into logs that the agent might follow when diagnosing errors.
  • Ingestion points: Outputs from cpanel log:errors, cpanel uapi, and cpanel api2 commands found in SKILL.md.
  • Boundary markers: The instructions do not define clear boundaries or specific "ignore" rules for the content returned by these tools.
  • Capability inventory: The agent can execute a wide range of cPanel operations via the cpanel CLI (as described in the "Escape hatch" section), including account modifications and file deletions.
  • Sanitization: There are no mentioned mechanisms for sanitizing or validating the output from the hosting environment before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill relies on a local binary engine bin/cpanel to perform all hosting operations. It constructs and executes shell commands based on user intent and developer-provided templates (e.g., cpanel uapi <Module> <function>). The tool search order includes the current directory and the home directory for configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 01:35 AM
Security Audit — agent-trust-hub — cpanel-toolkit