gitlawb
Fail
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the user to install its CLI tool by downloading a script from an external URL and piping it directly into the shell (
curl -sSf https://gitlawb.com/install.sh | sh). This pattern provides no opportunity for the user or agent to inspect the code before execution. - Evidence found in
SKILL.mdandscripts/setup.sh. - [EXTERNAL_DOWNLOADS]: The skill downloads and installs several external components from non-whitelisted sources at runtime, including the
glCLI binary and associated git remote helpers. - Evidence includes npm packages (
@gitlawb/gl,@gitlawb/opencode) and thegitlawb.cominstall script. - [CREDENTIALS_UNSAFE]: The skill requires the use of a private key (
ETH_PRIVATE_KEY) for on-chain transactions and explicitly provides examples where the key is passed as a command-line argument (--private-key <key>). This practice can leak sensitive credentials to system logs, process lists, and shell history. - Evidence found in
SKILL.mdunder the 'Base L2 Name Registry' section. - [COMMAND_EXECUTION]: The skill makes extensive use of a custom CLI tool (
gl) to perform network and file system operations, which is executed via shell commands. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it ingests and processes untrusted data from a decentralized network.
- Ingestion points: Untrusted data enters the agent context through repository trees, pull request details, issue bodies, and task payloads retrieved from decentralized nodes via tools like
repo_tree,pr_view, andissue_view. - Boundary markers: The skill does not employ any delimiters or specific instructions to isolate or ignore potentially malicious content embedded in the git data.
- Capability inventory: The skill has the ability to execute shell commands (
gl), perform network requests to decentralized nodes, and write to the local file system (git clone). - Sanitization: There is no evidence of sanitization, validation, or escaping of the content fetched from the network before it is passed to the AI agent.
Recommendations
- HIGH: Downloads and executes remote code from: https://gitlawb.com/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata