skills/letta-ai/skills/1password/Gen Agent Trust Hub

1password

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to interact with the 1Password CLI and manage terminal sessions via tmux. It utilizes tmux capture-pane to retrieve command results into the agent's context as shown in the workflow examples in SKILL.md.
  • [PRIVILEGE_ESCALATION]: The instructions include the use of sudo for the installation of the tmux dependency on Linux systems (e.g., sudo apt install tmux), which is a standard administrative procedure for package management.
  • [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest data from 1Password vaults, there is an inherent surface for indirect prompt injection if the stored secrets contain malicious instructions.
  • Ingestion points: Content is brought into the agent's context via tmux capture-pane after running op commands, as described in the tmux session example in SKILL.md.
  • Boundary markers: The instructions include explicit guardrails for the agent to avoid pasting secrets into logs or chat, though it does not define structural delimiters for the secret content itself.
  • Capability inventory: The skill uses system commands (tmux, op) and package managers (apt, brew, dnf).
  • Sanitization: The skill relies on 1Password CLI's masking and internal agent guardrails to prevent sensitive data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — 1password