skills/boshu2/agentops/review/Gen Agent Trust Hub

review

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The file references/BUG_SCANNER.md contains instructions for installing the 'ultimate_bug_scanner' tool using a highly dangerous pattern: curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/ultimate_bug_scanner/master/install.sh" | bash -s -- --easy-mode. This pattern executes arbitrary remote code from an untrusted GitHub repository (Dicklesworthstone) directly in the user's shell, which is a significant security risk if the repository or script is compromised.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of GitHub Pull Request diffs and agent-generated output.
  • Ingestion points: Diff content is fetched using gh pr diff and git diff as described in SKILL.md (Step 1).
  • Boundary markers: The instructions lack explicit boundary markers or 'ignore embedded instructions' warnings when presenting the diff content to the agent for assessment.
  • Capability inventory: The skill utilizes several powerful CLI tools, including gh, git, find, and custom binaries ao, ubs, br, and bv.
  • Sanitization: There is no evidence of sanitization or filtering of the fetched diff content before it is processed by the agent.
  • [COMMAND_EXECUTION]: The skill makes extensive use of system commands and external binaries to perform its tasks. While consistent with a code review tool, the use of ao lookup, ubs, br, and bv represents an expanded attack surface, especially since these tools are used to process potentially malicious code changes and metadata.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 05:10 PM
Security Audit — agent-trust-hub — review