cli-anything-iterm2-ctl
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides tools to read terminal scrollback and session snapshots (
session scrollback,app snapshot). This allows the agent to ingest untrusted data from the terminal environment, such as the contents of log files or command outputs, which could contain malicious instructions designed to influence the agent's behavior. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
cli-anything-iterm2Python package from PyPI, a third-party repository.
Audit Metadata