skill-installer

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads repository ZIP archives from GitHub's infrastructure. It implements a specific security function, _safe_extract_zip, which validates that filenames within the archive do not attempt directory traversal to write files outside the intended destination.- [REMOTE_CODE_EXECUTION]: This utility is designed to download and install executable skills (scripts and instructions) from remote repositories. This is the primary function of the skill and allows the agent's capabilities to be extended dynamically.- [COMMAND_EXECUTION]: The script install-skill-from-github.py invokes the git binary using subprocess.run to perform sparse checkouts. It uses list-based arguments rather than shell strings, which mitigates command injection risks, and validates all repository paths and skill names before execution.- [INDIRECT_PROMPT_INJECTION]: The skill provides an attack surface for indirect prompt injection because it ingests untrusted data from external repositories (ingestion point: install-skill-from-github.py). The skill lacks explicit boundary markers for the content it installs but implements sanitization through path validation and archive safety checks. Its capability inventory includes file system writes and subprocess execution (scripts in install-skill-from-github.py).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:44 AM
Security Audit — agent-trust-hub — skill-installer