cohere-install-auth

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Installs the official Cohere SDKs (cohere-ai and cohere) from official package registries. These are established tools from a well-known service provider.
  • [COMMAND_EXECUTION]: Provides standard shell commands to install dependencies and configure environment variables for API key management.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data. 1. Ingestion points: External data is processed via the messages array in the verification code snippets provided in SKILL.md. 2. Boundary markers: The provided examples do not include explicit delimiters or instructions to ignore embedded commands. 3. Capability inventory: The skill utilizes shell tools for installation and makes network requests to the Cohere API. 4. Sanitization: No explicit input sanitization or validation logic is included in the basic verification snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 04:15 PM
Security Audit — agent-trust-hub — cohere-install-auth