cli-anything-eth2-quickstart
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is a wrapper for the
chimera-defi/eth2-quickstartrepository. It relies on the shell scripts and automation logic provided by this external source to perform node bootstrapping and client installation. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from the external repository and the output of node management commands, which could potentially be manipulated to influence the agent's logic.
- Ingestion points: The skill reads repository configuration files and processes structured JSON output from node health checks.
- Boundary markers: There are no explicit instructions for the agent to treat external repository content or tool outputs as untrusted data using delimiters or specific isolation prompts.
- Capability inventory: The skill is capable of executing complex deployment shell scripts, modifying system configurations (Nginx/Caddy), and writing to environment files (
config/user_config.env). - Sanitization: The skill does not define methods for validating or sanitizing the content of the repository or the structured output from the wrapped CLI before processing.
- [COMMAND_EXECUTION]: The skill executes a series of shell commands for installing Ethereum clients, configuring validators, and managing RPC stacks. These operations are performed via a wrapper tool that calls scripts in the local repository checkout.
Audit Metadata