cyrus-setup-endpoint

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the ngrok agent from an official Amazon S3 bucket (ngrok-agent.s3.amazonaws.com). This is a well-known service's distribution infrastructure.
  • [COMMAND_EXECUTION]: The skill utilizes several shell commands including grep, mkdir, cat, printf, which, tar, read, and pbpaste to manage environment variables and configuration files.
  • [PRIVILEGE_ESCALATION]: The skill uses sudo during the ngrok installation process to move the binary to /usr/local/bin. This is a routine administrative task for software installation.
  • [PROMPT_INJECTION]: The skill contains a directive instructing the agent to avoid using standard file-reading tools on the ~/.cyrus/ directory. This is a defensive instruction designed to ensure secrets (like API tokens) remain within the user's shell environment and are not read into the LLM's conversation context or logs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:14 AM
Security Audit — agent-trust-hub — cyrus-setup-endpoint