skills/connorads/remobi/remobi-setup/Gen Agent Trust Hub

remobi-setup

Warn

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs silent environment discovery by executing shell commands (node, tmux, which) to inspect prerequisites and tool availability without prior user disclosure. Detailed technical analysis formatted as bullet points.
  • [PRIVILEGE_ESCALATION]: The skill provides instructions for using sudo pmset to modify system-wide power management settings on macOS to prevent sleep, which requires elevated privileges.
  • [EXTERNAL_DOWNLOADS]: The skill initiates the installation of the remobi package globally via npm and the tmux multiplexer through system package managers (brew, apt, dnf).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes content from local configuration files (~/.tmux.conf, ~/.config/tmux/tmux.conf) and terminal outputs (tmux list-keys) to inform its configuration logic.
  • Ingestion points: Reads tmux.conf files and multiplexer command outputs in SKILL.md.
  • Boundary markers: No delimiters or warnings are used when processing these external inputs.
  • Capability inventory: The skill can perform package installations, system configuration changes via sudo, and service management.
  • Sanitization: There is no evidence of sanitization or validation of the ingested configuration content.
  • [DYNAMIC_EXECUTION]: The skill programmatically generates a TypeScript configuration file (remobi.config.ts) and validates it by executing the remobi server with a dummy command.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 29, 2026, 03:01 AM
Security Audit — agent-trust-hub — remobi-setup