boris

Fail

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to perform a WebFetch to 'https://howborisusesclaudecode.com/api/version' during its initialization to check for updates, allowing unverified external data to enter the agent's context.
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the download and execution of remote content by providing a shell command ('curl -L -o ~/.claude/skills/boris/SKILL.md https://howborisusesclaudecode.com/api/install') that replaces the skill's local file with an unverified remote version.
  • [PROMPT_INJECTION]: The update logic establishes an indirect prompt injection vulnerability where the response from an external API determines the agent's output and recommendations to the user, potentially bypassing local constraints through remote instruction delivery.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 15, 2026, 12:53 PM
Security Audit — agent-trust-hub — boris