audit-registry-listing

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and run 'install one-liners' from external, untrusted sources (such as READMEs and registry pages) to verify the installation success path. This creates an attack surface where a malicious repository could provide dangerous commands designed to be executed by the auditing agent.
  • Ingestion points: External README files, npm/PyPI metadata, and ecosystem manifests (SKILL.md).
  • Boundary markers: Absent; the skill does not provide instructions for the agent to use delimiters or to ignore embedded instructions when reading or executing these commands.
  • Capability inventory: The skill requires the ability to execute shell commands (e.g., npx, npm pack) to audit the package artifacts and installation process.
  • Sanitization: Absent; there is no requirement to sanitize or validate the 'install one-liner' before execution.
  • [COMMAND_EXECUTION]: The auditing process involves executing shell commands, including npm pack --dry-run and package installation one-liners. While the skill mentions using a 'clean profile' as a mitigation, executing commands derived from external sources poses an inherent risk if the source content is not thoroughly validated.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 05:41 PM
Security Audit — agent-trust-hub — audit-registry-listing