hyprland

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The README.md and install.sh files recommend an installation procedure that pipes a remote script directly into bash (curl -fsSL https://raw.githubusercontent.com/marceloeatworld/hyprland-ai-skill/main/install.sh | bash). This execution pattern allows unverified remote code to run with the user's local shell privileges.
  • [EXTERNAL_DOWNLOADS]: The skill is configured to download resources from external sources, including a personal GitHub repository and the official Hyprland wiki repository (https://github.com/hyprwm/hyprland-wiki.git).
  • [COMMAND_EXECUTION]: The skill includes shell scripts like generate-references.sh that execute multiple system commands, including git clone, mktemp, and file operations to update local documentation files.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates by ingesting and interpreting external documentation from the Hyprland Wiki. This content acts as a potential ingestion point for malicious instructions.
  • Ingestion points: Local reference files in the references/ directory and remote content fetched from raw.githubusercontent.com.
  • Boundary markers: The SKILL.md instructions do not define boundary markers (such as XML tags or delimiters) or provide explicit warnings for the agent to disregard instructions or commands contained within the documentation.
  • Capability inventory: The agent environment typically has access to terminal execution and file-system tools. The documentation files contain examples of dangerous commands (e.g., modifying sudoers files via sudo tee in hyprshutdown.md) that an agent might inadvertently follow if not properly constrained.
  • Sanitization: No sanitization or filtering logic is present to ensure that the content fetched from the wiki is safe for the agent to process.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/marceloeatworld/hyprland-ai-skill/main/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 03:29 AM
Security Audit — agent-trust-hub — hyprland