listenhub-cli
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the
@marswave/listenhub-clipackage from the public NPM registry. This package belongs to the skill vendor's namespace and is required for the intended functionality. - [COMMAND_EXECUTION]: The skill uses shell commands to manage the lifecycle of the ListenHub tool, including checking authentication status (
listenhub auth status), performing logins (listenhub auth login), and installing the CLI globally vianpm install -g. - [INDIRECT_PROMPT_INJECTION]: The skill functions as a router that identifies user intent from potentially untrusted messages to delegate tasks to other skills.
- Ingestion points: User-supplied text and potential content from external URLs (via the
/content-parserroute). - Boundary markers: None present; the skill identifies keywords directly within the user input.
- Capability inventory: Shell execution capabilities for tool installation and authentication management.
- Sanitization: The skill does not explicitly sanitize keywords before matching or delegate to sub-skills, relying on subsequent skill logic for safety.
Audit Metadata