oneleet
Fail
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
oneleet auth import-cdpcommand allows the agent to import authentication session state and cookies directly from a Chrome browser with remote debugging enabled. - [EXTERNAL_DOWNLOADS]: The skill uses
npx -y oneleet-clito download and execute an unofficial package from the npm registry. - [COMMAND_EXECUTION]: Requires the execution of various shell commands, including the
oneleetCLI binary and local build scripts likenpm installandnpm run build. - [DATA_EXFILTRATION]: Accesses and processes high-sensitivity information such as HIPAA reports, security remediation queues, and infrastructure monitor data from the Oneleet platform.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection when processing output from the
oneleetCLI; ingestion points include all CLI command outputs (SKILL.md), boundary markers are absent, the capability inventory includes shell command execution, and no sanitization of tool output is performed.
Recommendations
- AI detected serious security threats
Audit Metadata