review
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The file
references/BUG_SCANNER.mdcontains instructions for installing the 'ultimate_bug_scanner' tool using a highly dangerous pattern:curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/ultimate_bug_scanner/master/install.sh" | bash -s -- --easy-mode. This pattern executes arbitrary remote code from an untrusted GitHub repository (Dicklesworthstone) directly in the user's shell, which is a significant security risk if the repository or script is compromised. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of GitHub Pull Request diffs and agent-generated output.
- Ingestion points: Diff content is fetched using
gh pr diffandgit diffas described inSKILL.md(Step 1). - Boundary markers: The instructions lack explicit boundary markers or 'ignore embedded instructions' warnings when presenting the diff content to the agent for assessment.
- Capability inventory: The skill utilizes several powerful CLI tools, including
gh,git,find, and custom binariesao,ubs,br, andbv. - Sanitization: There is no evidence of sanitization or filtering of the fetched diff content before it is processed by the agent.
- [COMMAND_EXECUTION]: The skill makes extensive use of system commands and external binaries to perform its tasks. While consistent with a code review tool, the use of
ao lookup,ubs,br, andbvrepresents an expanded attack surface, especially since these tools are used to process potentially malicious code changes and metadata.
Recommendations
- AI detected serious security threats
Audit Metadata