skill-installer
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads code from arbitrary GitHub repositories using ZIP archives from codeload.github.com and Git clones.
- [COMMAND_EXECUTION]: Executes system commands via the subprocess module to run git for cloning and sparse checkouts using parameters derived from user input.
- [REMOTE_CODE_EXECUTION]: Facilitates the installation of new functional code into the agent's runtime environment, which leads to the execution of that code during agent operation.
- [PROMPT_INJECTION]: Susceptible to indirect prompt injection where an attacker could name directories in a repository to contain malicious instructions for the agent. Ingestion points: scripts/list-skills.py (directory listing from GitHub API). Boundary markers: None. Capability inventory: subprocess.run and shutil.copytree in scripts/install-skill-from-github.py. Sanitization: None.
Audit Metadata