kit-extensions
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The documentation provides multiple code patterns for executing shell commands using the
os/execpackage. Specifically, it demonstrates how to register slash commands and tools that run shell processes (e.g.,exec.Command(\"sh\", \"-c\", args)). It mitigates this risk by including a 'Tool Call Blocking' pattern that advises developers to use allowlists and fail-closed logic when inspecting potentially dangerous commands.\n- [EXTERNAL_DOWNLOADS]: The skill describes thekit installcommand, which allows users to download and install extensions directly from remote Git repositories (e.g., GitHub). This is a core distribution mechanism for the Kit platform. The documentation provides clear instructions on repository structure and installation workflows.\n- [INDIRECT_PROMPT_INJECTION]: The skill documents API capabilities that allow extensions to modify the agent's behavior at runtime. This includesOnBeforeAgentStartfor injecting system prompts andOnContextPreparefor filtering or injecting messages into the conversation history. These are intended extensibility features that allow developers to augment agent logic.
Audit Metadata