opencli-autofix
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data derived from external websites—such as DOM snapshots and network logs—to determine which local files to edit and how to patch them. An attacker-controlled website could potentially provide content designed to influence the agent's code-patching logic.
- Ingestion points:
summary.md(trace artifact) and DOM snapshots in thestate/directory generated after interacting with external sites. - Boundary markers: The skill defines "Safety Boundaries" that restrict modifications to the
adapterSourcePathfound in the trace and prohibit changes to core project files likepackage.jsonorsrc/. - Capability inventory:
Bash,Read,Edit, andWritetools are used to analyze, modify, and execute local source code. - Sanitization: The skill lacks formal validation to ensure the
adapterSourcePathextracted from a trace summary points to a legitimate adapter rather than a sensitive system file, relying instead on agent interpretation of the "authoritative location." - [COMMAND_EXECUTION]: The skill uses
Bashto executeopenclifor diagnostic purposes andghfor filing issues on the vendor's GitHub repository. - [DYNAMIC_EXECUTION]: The skill instructs the agent to generate code patches and overwrite local files at runtime, which are then immediately executed to verify the fix.
- [DATA_EXFILTRATION]: The skill facilitates sending diagnostic data (trace summaries and code descriptions) to GitHub via
gh issue create. This risk is mitigated by instructions requiring the agent to present a draft and obtain explicit user approval before filing.
Audit Metadata