skills/loadchange/skills/grok/Gen Agent Trust Hub

grok

Fail

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Documentation in SKILL.md and scripts/grok_acp.py references installing the grok CLI using a remote script (curl -fsSL https://x.ai/cli/install.sh | bash). The source domain x.ai belongs to the well-known technology provider xAI.\n- [COMMAND_EXECUTION]: The skill uses subprocess.Popen in scripts/grok_acp.py to drive the locally installed grok binary over the Agent Client Protocol (ACP). It properly uses list-based arguments to prevent shell injection.\n- [PROMPT_INJECTION]: The skill ingests untrusted external data via X and web search, creating an indirect prompt injection surface. Mandatory Evidence Chain: 1. Ingestion points: X search and web results via x_search and web_search tools. 2. Boundary markers: The skill instructs the agent to cite and quote verbatim, but lacks strict programmatic delimiters. 3. Capability inventory: Subprocess execution of the grok CLI and network downloads via urllib. 4. Sanitization: No content filtering or sanitization is applied to ingested search data. Risk is partially mitigated by a restricted SEARCH_PROFILE that limits the internal agent's tools.\n- [DATA_EXFILTRATION]: The script scripts/grok_acp.py uses urllib.request to download generated images and videos from remote uploaded_url locations provided by the Grok agent's output. While expected for media generation, this involves network requests to external domains.
Recommendations
  • HIGH: Downloads and executes remote code from: https://x.ai/cli/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 22, 2026, 04:00 AM
Security Audit — agent-trust-hub — grok