pair-agent
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches a setup script for the Bun runtime from bun.sh, a well-known service. The script's integrity is verified using a hardcoded SHA256 checksum before execution.
- [COMMAND_EXECUTION]: Executes the downloaded Bun installer script via the shell to set up the execution environment.
- [DATA_EXFILTRATION]: Facilitates remote access to the browser session through an ngrok tunnel. While this represents a significant network exposure surface, the skill includes explicit security warnings and requires user consent before enabling the tunnel.
- [INDIRECT_PROMPT_INJECTION]: As the skill allows a remote agent to read and interact with arbitrary web content, it creates an attack surface for indirect prompt injection from malicious websites.
- Ingestion points: Paired browser tabs reading HTML, text, and snapshots from external web pages.
- Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the content read from the web.
- Capability inventory: Navigating URLs, clicking elements, filling forms, taking screenshots, and executing JavaScript via eval.
- Sanitization: No specific sanitization or validation of the external web content is described.
Audit Metadata