cli-over-web
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard system CLI tools (e.g.,
npm,pip,gh,dig) for retrieving package information, repository metadata, and network records. This is a legitimate use case for a developer-oriented agent. - [EXTERNAL_DOWNLOADS]: The instructions encourage querying external registries (NPM, PyPI, Crates.io) and APIs via CLI tools. These operations are restricted to metadata retrieval and information lookups from well-known services.
- [SAFE]: The skill explicitly advises against security risks, such as hardcoding credentials, by recommending the use of environment variables for API tokens.
- [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by instructing the agent to process data from external sources like package descriptions or API responses.
- Ingestion points: CLI output from tools like
npm vieworgh api(SKILL.md). - Boundary markers: Not specified.
- Capability inventory: Shell execution for data lookup tools.
- Sanitization: No specific sanitization or escaping of external content is mentioned.
Audit Metadata