cli-anything-intelwatch
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation instructs the user to install
cli-anything-intelwatchvia pip. This package is not from a trusted or well-known vendor, presenting a risk associated with executing unverified code. - [COMMAND_EXECUTION]: The skill requires the execution of shell commands for installation and operation, including
pip install,node -v,npx -v, and specific tool commands likecli-anything-intelwatch profile. - [INDIRECT_PROMPT_INJECTION]: The tool aggregates 'deep profiles' and 'due diligence' from external domains. Since it processes untrusted web content from company websites, it is susceptible to malicious instructions embedded in HTML, metadata, or other on-page text.
Audit Metadata