cyrus-setup-repository
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes bash commands (
cyrus self-add-repo,cat,grep) to manage repository configurations. Thecyruscommand line tool represents a legitimate vendor utility matching the author context (cyrusagents). - [INDIRECT_PROMPT_INJECTION]: The skill exposes an untrusted input surface by interpolating user-supplied repository URLs and workspace names directly into shell commands without strict validation.
- Ingestion points: User input requested for Git repository URLs and workspace names in Step 2.
- Boundary markers: Absent. There are no delimiters or explicit instructions telling the agent to treat the input strictly as data or to isolate it.
- Capability inventory: The skill possesses full shell command execution capabilities via bash blocks in
SKILL.md. - Sanitization: Absent. The user-provided parameters are passed into commands without explicit prompt-level validation or sanitization guidelines.
Audit Metadata