skills/mabhub/skills/cli-over-web/Gen Agent Trust Hub

cli-over-web

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard system CLI tools (e.g., npm, pip, gh, dig) for retrieving package information, repository metadata, and network records. This is a legitimate use case for a developer-oriented agent.
  • [EXTERNAL_DOWNLOADS]: The instructions encourage querying external registries (NPM, PyPI, Crates.io) and APIs via CLI tools. These operations are restricted to metadata retrieval and information lookups from well-known services.
  • [SAFE]: The skill explicitly advises against security risks, such as hardcoding credentials, by recommending the use of environment variables for API tokens.
  • [PROMPT_INJECTION]: The skill introduces a surface for indirect prompt injection by instructing the agent to process data from external sources like package descriptions or API responses.
  • Ingestion points: CLI output from tools like npm view or gh api (SKILL.md).
  • Boundary markers: Not specified.
  • Capability inventory: Shell execution for data lookup tools.
  • Sanitization: No specific sanitization or escaping of external content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 03:06 PM
Security Audit — agent-trust-hub — cli-over-web