clerk-backend-api

Fail

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads OpenAPI specifications from Clerk's official GitHub repository to dynamically discover API endpoints and schemas.
  • Evidence: curl -s https://raw.githubusercontent.com/clerk/openapi-specs/main/bapi/${version_name} in SKILL.md.
  • Context: The downloaded content is piped into local parsing scripts (extract-tags.js, extract-tag-endpoints.sh) as data.
  • [COMMAND_EXECUTION]: A local helper script, scripts/execute-request.sh, is designed to search for and source environment files to load API credentials.
  • Evidence: source "$_envfile" used on .env and .env.local files discovered in the directory hierarchy.
  • Note: The skill instructions explicitly direct the agent not to use this specific script, reserving it for local developer use.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user input to define API paths and parameters, which creates a potential surface for indirect prompt injection.
  • Ingestion points: User-provided strings via the $ARGUMENTS variable in SKILL.md.
  • Boundary markers: No explicit delimiters or boundary markers are used when interpolating these arguments into command templates.
  • Capability inventory: The skill has access to shell execution (Bash) and network operations (WebFetch/curl).
  • Sanitization: There is no evidence of input validation or sanitization for the parameters provided by the user before they are included in API request bodies or shell commands.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/clerk/openapi-specs/main/bapi/${version_name} - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — clerk-backend-api