grok
Fail
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Documentation in
SKILL.mdandscripts/grok_acp.pyreferences installing thegrokCLI using a remote script (curl -fsSL https://x.ai/cli/install.sh | bash). The source domainx.aibelongs to the well-known technology provider xAI.\n- [COMMAND_EXECUTION]: The skill usessubprocess.Popeninscripts/grok_acp.pyto drive the locally installedgrokbinary over the Agent Client Protocol (ACP). It properly uses list-based arguments to prevent shell injection.\n- [PROMPT_INJECTION]: The skill ingests untrusted external data via X and web search, creating an indirect prompt injection surface. Mandatory Evidence Chain: 1. Ingestion points: X search and web results viax_searchandweb_searchtools. 2. Boundary markers: The skill instructs the agent to cite and quote verbatim, but lacks strict programmatic delimiters. 3. Capability inventory: Subprocess execution of thegrokCLI and network downloads viaurllib. 4. Sanitization: No content filtering or sanitization is applied to ingested search data. Risk is partially mitigated by a restrictedSEARCH_PROFILEthat limits the internal agent's tools.\n- [DATA_EXFILTRATION]: The scriptscripts/grok_acp.pyusesurllib.requestto download generated images and videos from remoteuploaded_urllocations provided by the Grok agent's output. While expected for media generation, this involves network requests to external domains.
Recommendations
- HIGH: Downloads and executes remote code from: https://x.ai/cli/install.sh - DO NOT USE without thorough review
Audit Metadata