cli-anything-rms
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill installs the
cli-anything-rmspackage directly from the HKUDS GitHub repository usingpip install. As HKUDS is a recognized vendor, this is a documented dependency acquisition. - [COMMAND_EXECUTION]: Provides a comprehensive suite of commands to interact with remote infrastructure, including
remote-access createfor starting remote sessions anddevices updatefor modifying remote system states. - [DATA_EXFILTRATION]: Includes the
files uploadcommand, which allows the agent to transmit local files to the RMS server. This capability could be abused to exfiltrate sensitive local data if the agent's logic is compromised. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes data from external sources such as device logs, alerts, and reports. This creates a vulnerability surface where an attacker controlling a remote device could inject malicious instructions into the agent's conversation flow.
- [CREDENTIALS_UNSAFE]: The skill manages sensitive credentials including API tokens via
config set, SMTP authentication details viasmtp create, and device passwords viapasswords update. While the documentation suggests safer methods like--password-stdin, the inherent capability to handle and store these secrets poses a risk.
Audit Metadata