audit-registry-listing
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and run 'install one-liners' from external, untrusted sources (such as READMEs and registry pages) to verify the installation success path. This creates an attack surface where a malicious repository could provide dangerous commands designed to be executed by the auditing agent.
- Ingestion points: External README files, npm/PyPI metadata, and ecosystem manifests (SKILL.md).
- Boundary markers: Absent; the skill does not provide instructions for the agent to use delimiters or to ignore embedded instructions when reading or executing these commands.
- Capability inventory: The skill requires the ability to execute shell commands (e.g.,
npx,npm pack) to audit the package artifacts and installation process. - Sanitization: Absent; there is no requirement to sanitize or validate the 'install one-liner' before execution.
- [COMMAND_EXECUTION]: The auditing process involves executing shell commands, including
npm pack --dry-runand package installation one-liners. While the skill mentions using a 'clean profile' as a mitigation, executing commands derived from external sources poses an inherent risk if the source content is not thoroughly validated.
Audit Metadata