skills/fradser/dotclaude/acpx/Gen Agent Trust Hub

acpx

Warn

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill registry specifies commands that launch various CLI tools as adapters and includes an escape hatch via the --agent flag that allows for the execution of arbitrary shell commands.
  • [EXTERNAL_DOWNLOADS]: The skill instructions and registry utilize npx and uvx to fetch and execute several third-party packages, including @agentclientprotocol/codex-acp, @kilocode/cli, and fast-agent-mcp.
  • [REMOTE_CODE_EXECUTION]: Several components of the agent registry utilize npx -y and uvx, which facilitate the automatic download and execution of remote code at runtime without manual approval.
  • [PROMPT_INJECTION]: The skill contains instructions marked as 'CRITICAL' that explicitly override the agent's default behavior and internal examples to enforce a specific protocol using isolated SubAgents and independent result reflection.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 24, 2026, 06:58 PM
Security Audit — agent-trust-hub — acpx