skills/easychen/skills/sudoboard/Gen Agent Trust Hub

sudoboard

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill utilizes new Function within its local engine and preview scripts to evaluate JSX templates. This is a core feature enabling the rendering of custom dashboards but involves executing dynamically generated code.\n- [DYNAMIC_EXECUTION]: The engine.js script automatically attempts to install the mysql2 and pg Node.js drivers using npm install if the user configures a database source that requires them.\n- [COMMAND_EXECUTION]: The skill's Python and Shell scripts invoke several external utilities, including wrangler for Cloudflare deployment, openssl for encrypted configuration bundling, and node for data processing.\n- [EXTERNAL_DOWNLOADS]: In addition to NPM packages, the skill downloads demo wallpaper assets from the author's website (sudb.106001.xyz) during the setup process.\n- [REMOTE_CODE_EXECUTION]: The skill downloads and executes code via the NPM registry for database drivers and uses npx wrangler to deploy Cloudflare Workers.\n- [PERSISTENCE]: The install-skill.sh script automates the installation of the skill by creating symbolic links in the host application's skill directories (e.g., ~/.claude/skills).\n- [INDIRECT_PROMPT_INJECTION]: The tool is designed to ingest data from external APIs and databases to display on dashboards, which is a potential surface for indirect prompt injection. Ingestion points: External HTTP APIs and Database queries processed by engine.js. Boundary markers: None observed in data interpolation. Capability inventory: Includes file writes, network requests, and dynamic shell command execution. Sanitization: Employs a ReadOnlyGuard to prevent write operations in SQL queries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 10:21 AM