skill-installer

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads code from arbitrary GitHub repositories using ZIP archives from codeload.github.com and Git clones.
  • [COMMAND_EXECUTION]: Executes system commands via the subprocess module to run git for cloning and sparse checkouts using parameters derived from user input.
  • [REMOTE_CODE_EXECUTION]: Facilitates the installation of new functional code into the agent's runtime environment, which leads to the execution of that code during agent operation.
  • [PROMPT_INJECTION]: Susceptible to indirect prompt injection where an attacker could name directories in a repository to contain malicious instructions for the agent. Ingestion points: scripts/list-skills.py (directory listing from GitHub API). Boundary markers: None. Capability inventory: subprocess.run and shutil.copytree in scripts/install-skill-from-github.py. Sanitization: None.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — skill-installer