blucli-hardened

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill metadata in SKILL.md includes a Go installation directive that fetches the 'blu' command-line utility from a third-party GitHub repository (github.com/steipete/blucli).
  • [COMMAND_EXECUTION]: The skill uses the 'blu' binary to perform discovery and control operations for hardware devices on the local network.
  • [DATA_EXFILTRATION]: The skill handles local network topology data (IPs and device names). It includes explicit guardrail instructions prohibiting the transmission of this data to external network destinations.
  • [PROMPT_INJECTION]: The skill instructions and the accompanying SAFETY.md file contain robust patterns to resist prompt injection attempts that might aim to bypass security constraints or perform unauthorized network reconnaissance.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:30 PM
Security Audit — agent-trust-hub — blucli-hardened