skill-installer
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads repository ZIP archives from GitHub's infrastructure. It implements a specific security function,
_safe_extract_zip, which validates that filenames within the archive do not attempt directory traversal to write files outside the intended destination.- [REMOTE_CODE_EXECUTION]: This utility is designed to download and install executable skills (scripts and instructions) from remote repositories. This is the primary function of the skill and allows the agent's capabilities to be extended dynamically.- [COMMAND_EXECUTION]: The scriptinstall-skill-from-github.pyinvokes thegitbinary usingsubprocess.runto perform sparse checkouts. It uses list-based arguments rather than shell strings, which mitigates command injection risks, and validates all repository paths and skill names before execution.- [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection because it ingests untrusted data from external repositories (ingestion point:install-skill-from-github.py). The skill lacks explicit boundary markers for the content it installs but implements sanitization through path validation and archive safety checks. Its capability inventory includes file system writes and subprocess execution (scripts ininstall-skill-from-github.py).
Audit Metadata