cyrus-setup-repository

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes bash commands (cyrus self-add-repo, cat, grep) to manage repository configurations. The cyrus command line tool represents a legitimate vendor utility matching the author context (cyrusagents).
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes an untrusted input surface by interpolating user-supplied repository URLs and workspace names directly into shell commands without strict validation.
  • Ingestion points: User input requested for Git repository URLs and workspace names in Step 2.
  • Boundary markers: Absent. There are no delimiters or explicit instructions telling the agent to treat the input strictly as data or to isolate it.
  • Capability inventory: The skill possesses full shell command execution capabilities via bash blocks in SKILL.md.
  • Sanitization: Absent. The user-provided parameters are passed into commands without explicit prompt-level validation or sanitization guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:14 AM
Security Audit — agent-trust-hub — cyrus-setup-repository