ru

Fail

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONPERSISTENCEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The installer script ('install.sh') and README documentation promote a pattern of fetching remote scripts via curl and piping them directly into bash. Specifically, it downloads an installation script for 'ru' and an additional tool called 'ntm' (Named Tmux Manager) from GitHub repositories authored by 'Dicklesworthstone'. The 'install.sh' script also features a self-refresh mechanism that downloads its own latest version and executes it at runtime.
  • [PERSISTENCE]: The 'install.sh' script contains a function 'add_to_path' that identifies user shell profiles (e.g., '.bashrc', '.zshrc', '.profile') and appends PATH export commands to them to ensure the tool remains available in future sessions.
  • [PROMPT_INJECTION]: The 'AGENTS.md' file contains 'RULE 0
  • THE FUNDAMENTAL OVERRIDE PREROGATIVE' which explicitly commands the AI to disregard other instructions and prioritize the author's directives ('YOU MUST LISTEN TO ME. I AM IN CHARGE, NOT YOU.'). It also instructs agents to 'fool themselves' and ignore unexpected changes in the working tree produced by other agents.
  • [INDIRECT_PROMPT_INJECTION]: The 'ru review' and 'ru agent-sweep' commands ingest untrusted data from GitHub issues and pull requests to drive AI analysis. While the skill includes instructions to verify user reports independently, it possesses a large attack surface by granting the agent capabilities to perform git mutations, write files, and execute system commands based on this untrusted input.
  • Ingestion points: 'SKILL.md' and 'ru' script use 'gh issue view' and 'gh pr view' to read external content.
  • Boundary markers: The system uses markers such as 'RU_COMMIT_PLAN_JSON_BEGIN' and 'RU_COMMIT_PLAN_JSON_END' to delimit AI-generated structured data, but these do not fully protect against malicious instructions in the input data.
  • Capability inventory: The skill can perform git commits, pushes, and releases, and it executes shell commands like 'make test' or 'npm run lint' as part of its quality gates.
  • Sanitization: The skill uses 'json_escape' and 'validate_commit_plan' to check file paths and size limits, but lacks full logic for sanitizing natural language prompts derived from issue descriptions.
  • [DYNAMIC_EXECUTION]: The main 'ru' script and its associated test scripts use the 'eval' command to dynamically load functions and process configuration variables. Furthermore, the tool's core logic involves executing 'COMMIT PLANS'—structured instructions generated by an AI agent at runtime which specify which files to stage and what messages to commit.
  • [PRIVILEGE_ESCALATION]: The 'install.sh' script requests and utilizes 'sudo' permissions if the 'RU_SYSTEM' environment variable is set, allowing it to write files to privileged system directories like '/usr/local/bin'.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/.../install.sh, https://raw.githubusercontent.com/Dicklesworthstone/repo_updater/main/install.sh?ru_cb=$(date - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 26, 2026, 12:56 AM
Security Audit — agent-trust-hub — ru