remote-from-telegram
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The instructions recommend using
npx ai-devkit@latestif the local binary is unavailable, which fetches and executes the most recent version of the package from the NPM registry at runtime. - [COMMAND_EXECUTION]: The skill executes various system commands through the
ai-devkitutility to list agents, channels, and manage bridge processes. - [PRIVILEGE_ESCALATION]: The skill explicitly directs the agent to run commands "outside filesystem sandboxes" to inspect host-level agent and channel state, which is a request to bypass standard security isolation and agent constraints.
Audit Metadata