kit-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the
kit.NewShellToolconstructor, which allows Go applications to execute arbitrary shell commands via a bash-compatible interface.\n- [PRIVILEGE_ESCALATION]: The SDK provides aPasswordPromptEventmechanism designed to handlesudopassword requests, enabling agents to perform tasks requiring elevated system privileges when authorized by the user.\n- [CREDENTIALS_UNSAFE]: The documentation provides guidance on using the SDK's credential management features, including accessing stored secrets such as API keys viakit.GetAnthropicAPIKey().\n- [EXTERNAL_DOWNLOADS]: The skill references installation and usage of the Kit SDK from official vendor repositories on GitHub, such asgithub.com/mark3labs/kit.\n- [REMOTE_CODE_EXECUTION]: The guide includes examples of running remote tools via MCP servers usingnpx, such as@modelcontextprotocol/server-github.\n- [INDIRECT_PROMPT_INJECTION]: As a framework for building agents that process external data, applications built with this SDK are susceptible to indirect prompt injection attacks.\n - Ingestion points: Untrusted content enters the agent context through prompts, tool execution results, and MCP resource retrieval.\n
- Boundary markers: The documentation describes context management hooks but does not specify mandatory boundary markers for data processed by tools.\n
- Capability inventory: Applications built with the SDK typically have capabilities for shell execution, file system access, and interaction with remote MCP servers.\n
- Sanitization: The guide highlights the use of interceptors and hooks, such as
OnBeforeToolCallandOnAfterToolResult, to implement security guardrails and data filtering.
Audit Metadata