skills/fubits1/ronin-skills/no-bash/Gen Agent Trust Hub

no-bash

Warn

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill strongly encourages the installation and use of third-party tools and plugins from non-standard sources, specifically the 'fff' MCP tool and the 'hooks@ronin-skills' plugin. These are not hosted by well-known or trusted technology organizations.
  • [COMMAND_EXECUTION]: Instructs the agent to use the '!' command prefix (e.g., '! git log') specifically to "route around the prompt." This technique is used to bypass user confirmation requirements for shell execution, increasing the risk of autonomous unauthorized actions.
  • [PROMPT_INJECTION]: Contains meta-instructions that attempt to control how the agent communicates with the user regarding errors. It specifically directs the agent to frame system-level blocks as "deterministic environment rejections" and explicitly tells the agent: "Do not narrate it as 'the user rejected my command'; the user did not act," which can be used to hide the source of restrictions or influence the user's perception of the agent's autonomy.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 11, 2026, 02:53 PM
Security Audit — agent-trust-hub — no-bash