cli-anything-rms

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill installs the cli-anything-rms package directly from the HKUDS GitHub repository using pip install. As HKUDS is a recognized vendor, this is a documented dependency acquisition.
  • [COMMAND_EXECUTION]: Provides a comprehensive suite of commands to interact with remote infrastructure, including remote-access create for starting remote sessions and devices update for modifying remote system states.
  • [DATA_EXFILTRATION]: Includes the files upload command, which allows the agent to transmit local files to the RMS server. This capability could be abused to exfiltrate sensitive local data if the agent's logic is compromised.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external sources such as device logs, alerts, and reports. This creates a vulnerability surface where an attacker controlling a remote device could inject malicious instructions into the agent's conversation flow.
  • [CREDENTIALS_UNSAFE]: The skill manages sensitive credentials including API tokens via config set, SMTP authentication details via smtp create, and device passwords via passwords update. While the documentation suggests safer methods like --password-stdin, the inherent capability to handle and store these secrets poses a risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 05:21 PM
Security Audit — agent-trust-hub — cli-anything-rms