shell-bash

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a technical reference guide and boilerplate provider for writing shell scripts, Makefiles, and justfiles. All provided code snippets follow industry-standard security best practices.
  • [DYNAMIC_EXECUTION]: The skill proactively identifies eval "$user_input" as a high-risk anti-pattern in its documentation, explicitly warning the agent and user against command injection vulnerabilities.
  • [COMMAND_EXECUTION]: The skill references standard development tools such as git, docker, curl, and jq. These are listed as required dependencies for the automated tasks the skill is designed to support, which is consistent with its stated purpose.
  • [DATA_EXFILTRATION]: While the skill contains examples using curl, these are documented neutrally as patterns for interacting with APIs (e.g., fetching a health status) rather than for exfiltrating sensitive local data.
  • [PRIVILEGE_ESCALATION]: The skill includes an example for writing to /etc/myapp/config.yml. While /etc is a system-sensitive directory, the snippet is provided as a best-practice example for performing 'atomic writes' (writing to a temporary file before moving it to the destination) to prevent configuration corruption.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:50 AM
Security Audit — agent-trust-hub — shell-bash