cpanel-toolkit
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes data from external sources, specifically cPanel error logs and API responses, creating a surface for indirect prompt injection. A malicious entity could potentially inject instructions into logs that the agent might follow when diagnosing errors.
- Ingestion points: Outputs from
cpanel log:errors,cpanel uapi, andcpanel api2commands found inSKILL.md. - Boundary markers: The instructions do not define clear boundaries or specific "ignore" rules for the content returned by these tools.
- Capability inventory: The agent can execute a wide range of cPanel operations via the
cpanelCLI (as described in the "Escape hatch" section), including account modifications and file deletions. - Sanitization: There are no mentioned mechanisms for sanitizing or validating the output from the hosting environment before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill relies on a local binary engine
bin/cpanelto perform all hosting operations. It constructs and executes shell commands based on user intent and developer-provided templates (e.g.,cpanel uapi <Module> <function>). The tool search order includes the current directory and the home directory for configuration files.
Audit Metadata