oneleet

Fail

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The oneleet auth import-cdp command allows the agent to import authentication session state and cookies directly from a Chrome browser with remote debugging enabled.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx -y oneleet-cli to download and execute an unofficial package from the npm registry.
  • [COMMAND_EXECUTION]: Requires the execution of various shell commands, including the oneleet CLI binary and local build scripts like npm install and npm run build.
  • [DATA_EXFILTRATION]: Accesses and processes high-sensitivity information such as HIPAA reports, security remediation queues, and infrastructure monitor data from the Oneleet platform.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection when processing output from the oneleet CLI; ingestion points include all CLI command outputs (SKILL.md), boundary markers are absent, the capability inventory includes shell command execution, and no sanitization of tool output is performed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 10, 2026, 03:08 AM
Security Audit — agent-trust-hub — oneleet