csctf
Fail
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions facilitate the download of an installation script (
install.sh) from the author's repository on GitHub. - Evidence:
curl -fsSL https://raw.githubusercontent.com/Dicklesworthstone/chat_shared_conversation_to_file/main/install.shinSKILL.md. - [REMOTE_CODE_EXECUTION]: The recommended installation method involves piping a remote shell script directly into the bash interpreter.
- Evidence:
curl -fsSL .../install.sh | bashinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The tool is designed to ingest and process untrusted external data in the form of AI chat transcripts from various providers, which could contain malicious instructions targeting the agent or the export process.
- Ingestion points: Accepts public share URLs from ChatGPT, Gemini, Grok, and Claude as input via the CLI.
- Boundary markers: The skill uses Turndown for Markdown conversion and whitespace normalization, though these are primarily for formatting rather than security boundaries.
- Capability inventory: The tool performs network requests to scrape chat providers, writes files to the local filesystem (transcripts and configuration), and integrates with the GitHub CLI (
gh) for automated repository publishing. - Sanitization: The tool implements 'Zero JavaScript' output and strips specific metadata/citation attributes during conversion to mitigate risks in the resulting HTML twin.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/Dicklesworthstone/chat_shared_conversation_to_file/main/install.sh - DO NOT USE without thorough review
Audit Metadata