cli-hub-meta-skill
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill facilitates the installation of the
cli-anything-hubpackage and various tool wrappers (e.g.,cli-anything-gimp) from public registries. These dependencies originate from third-party sources (HKUDS/reeceyang) not explicitly associated with the skill author.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from an external catalog URL, creating an attack surface for indirect prompt injection.\n - Ingestion points: Remote markdown catalog at
https://reeceyang.sgp1.cdn.digitaloceanspaces.com/SKILL.md(hosted on a well-known service).\n - Boundary markers: None; the agent is instructed to treat the remote content as an authoritative source for installation commands and usage patterns.\n
- Capability inventory: Subprocess execution via
pipand shell command execution for the installed professional software interfaces.\n - Sanitization: No validation or filtering is performed on the remote instructions before they are incorporated into the agent's context.\n- [COMMAND_EXECUTION]: The tool is designed to provide agents with CLI access to professional software backends. This provides the agent with extensive local system access based on the specific capabilities of the installed tools, which should be monitored for unintended command sequences.
Audit Metadata