skills/cipherstash/stack/stash-cli/Gen Agent Trust Hub

stash-cli

Pass

Audited by Gen Agent Trust Hub on May 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: Instructs the agent to run the stash CLI and various package managers for project initialization.
  • [EXTERNAL_DOWNLOADS]: Retrieves EQL SQL installation scripts from the vendor's GitHub repository when the --latest flag is used.
  • [INDIRECT_PROMPT_INJECTION]: Reads encryption plans from user-editable local files (.cipherstash/plan.md), creating a surface for indirect prompt injection.
  • [DATA_EXFILTRATION]: Accesses sensitive connection strings (DATABASE_URL) and authentication tokens required for database and API interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 21, 2026, 02:00 PM
Security Audit — agent-trust-hub — stash-cli