1password
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to interact with the 1Password CLI and manage terminal sessions via tmux. It utilizes
tmux capture-paneto retrieve command results into the agent's context as shown in the workflow examples in SKILL.md. - [PRIVILEGE_ESCALATION]: The instructions include the use of
sudofor the installation of the tmux dependency on Linux systems (e.g.,sudo apt install tmux), which is a standard administrative procedure for package management. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest data from 1Password vaults, there is an inherent surface for indirect prompt injection if the stored secrets contain malicious instructions.
- Ingestion points: Content is brought into the agent's context via
tmux capture-paneafter runningopcommands, as described in the tmux session example in SKILL.md. - Boundary markers: The instructions include explicit guardrails for the agent to avoid pasting secrets into logs or chat, though it does not define structural delimiters for the secret content itself.
- Capability inventory: The skill uses system commands (
tmux,op) and package managers (apt,brew,dnf). - Sanitization: The skill relies on 1Password CLI's masking and internal agent guardrails to prevent sensitive data exposure.
Audit Metadata