skills/google/sam/sam-mesh/Gen Agent Trust Hub

sam-mesh

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • Remote Installation Script: The skill provides a command to install the CLI tool using a script from https://sam-mesh.dev/install.sh piped to a shell. While common for software distribution, this pattern requires user verification of the source and script content before execution.
  • Indirect Prompt Injection Surface: The skill discovers and describes tools from remote mesh peers. This external metadata (such as tool names and descriptions) could potentially be used for indirect prompt injection if a peer is compromised. The skill mitigates this by requiring user approval for tools that have side effects and advising the agent to only call read-only tools autonomously.
  • Ingestion points: find_remote_tools and describe_remote_tool in SKILL.md fetch external data from the mesh.
  • Boundary markers: Instructions explicitly require user approval for state-mutating or high-risk tool calls.
  • Capability inventory: Accesses shell commands (sam-node), local files (API token), and network resources (curl).
  • Sanitization: Instructions emphasize verifying schemas and surfacing discovery errors clearly.
  • Local Command Execution: The skill involves running various sam-node commands to manage the node and mesh connectivity. The instructions emphasize that the agent should present these commands for user approval before they are run to maintain human-in-the-loop control.
  • Secure Credential Management: The skill handles a node API token for authentication to the mesh. It employs security-conscious techniques, such as process substitution (-H @<(...)) in curl commands, to ensure the token is not exposed in shell history, process listings, or command arguments.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 02:25 PM
Security Audit — agent-trust-hub — sam-mesh