remote-package-installer
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The script
install.shusespip installto fetch and install a package directly from a remote URL (https://packages.invalid/unsigned-tool.whl). This technique bypasses standard registry security checks and allows for the execution of arbitrary setup scripts or code contained within the remote archive. - [EXTERNAL_DOWNLOADS]: The skill initiates a download of executable content from an external, untrusted domain (
packages.invalid), posing a significant supply chain risk.
Recommendations
- AI detected serious security threats
Audit Metadata