skills/garrytan/gstack/pair-agent/Gen Agent Trust Hub

pair-agent

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches a setup script for the Bun runtime from bun.sh, a well-known service. The script's integrity is verified using a hardcoded SHA256 checksum before execution.
  • [COMMAND_EXECUTION]: Executes the downloaded Bun installer script via the shell to set up the execution environment.
  • [DATA_EXFILTRATION]: Facilitates remote access to the browser session through an ngrok tunnel. While this represents a significant network exposure surface, the skill includes explicit security warnings and requires user consent before enabling the tunnel.
  • [INDIRECT_PROMPT_INJECTION]: As the skill allows a remote agent to read and interact with arbitrary web content, it creates an attack surface for indirect prompt injection from malicious websites.
  • Ingestion points: Paired browser tabs reading HTML, text, and snapshots from external web pages.
  • Boundary markers: No specific delimiters or "ignore instructions" warnings are defined for the content read from the web.
  • Capability inventory: Navigating URLs, clicking elements, filling forms, taking screenshots, and executing JavaScript via eval.
  • Sanitization: No specific sanitization or validation of the external web content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:58 AM
Security Audit — agent-trust-hub — pair-agent