opencli-autofix

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data derived from external websites—such as DOM snapshots and network logs—to determine which local files to edit and how to patch them. An attacker-controlled website could potentially provide content designed to influence the agent's code-patching logic.
  • Ingestion points: summary.md (trace artifact) and DOM snapshots in the state/ directory generated after interacting with external sites.
  • Boundary markers: The skill defines "Safety Boundaries" that restrict modifications to the adapterSourcePath found in the trace and prohibit changes to core project files like package.json or src/.
  • Capability inventory: Bash, Read, Edit, and Write tools are used to analyze, modify, and execute local source code.
  • Sanitization: The skill lacks formal validation to ensure the adapterSourcePath extracted from a trace summary points to a legitimate adapter rather than a sensitive system file, relying instead on agent interpretation of the "authoritative location."
  • [COMMAND_EXECUTION]: The skill uses Bash to execute opencli for diagnostic purposes and gh for filing issues on the vendor's GitHub repository.
  • [DYNAMIC_EXECUTION]: The skill instructs the agent to generate code patches and overwrite local files at runtime, which are then immediately executed to verify the fix.
  • [DATA_EXFILTRATION]: The skill facilitates sending diagnostic data (trace summaries and code descriptions) to GitHub via gh issue create. This risk is mitigated by instructions requiring the agent to present a draft and obtain explicit user approval before filing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:00 PM
Security Audit — agent-trust-hub — opencli-autofix