remote-package-installer

Fail

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The script install.sh uses pip install to fetch and install a package directly from a remote URL (https://packages.invalid/unsigned-tool.whl). This technique bypasses standard registry security checks and allows for the execution of arbitrary setup scripts or code contained within the remote archive.
  • [EXTERNAL_DOWNLOADS]: The skill initiates a download of executable content from an external, untrusted domain (packages.invalid), posing a significant supply chain risk.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 9, 2026, 11:40 AM
Security Audit — agent-trust-hub — remote-package-installer