sam-mesh
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- Remote Installation Script: The skill provides a command to install the CLI tool using a script from
https://sam-mesh.dev/install.shpiped to a shell. While common for software distribution, this pattern requires user verification of the source and script content before execution. - Indirect Prompt Injection Surface: The skill discovers and describes tools from remote mesh peers. This external metadata (such as tool names and descriptions) could potentially be used for indirect prompt injection if a peer is compromised. The skill mitigates this by requiring user approval for tools that have side effects and advising the agent to only call read-only tools autonomously.
- Ingestion points:
find_remote_toolsanddescribe_remote_toolinSKILL.mdfetch external data from the mesh. - Boundary markers: Instructions explicitly require user approval for state-mutating or high-risk tool calls.
- Capability inventory: Accesses shell commands (
sam-node), local files (API token), and network resources (curl). - Sanitization: Instructions emphasize verifying schemas and surfacing discovery errors clearly.
- Local Command Execution: The skill involves running various
sam-nodecommands to manage the node and mesh connectivity. The instructions emphasize that the agent should present these commands for user approval before they are run to maintain human-in-the-loop control. - Secure Credential Management: The skill handles a node API token for authentication to the mesh. It employs security-conscious techniques, such as process substitution (
-H @<(...)) incurlcommands, to ensure the token is not exposed in shell history, process listings, or command arguments.
Audit Metadata