apm-usage
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- Remote Script Execution: The documentation provides commands to install the tool by downloading and executing scripts from domains like aka.ms. This is a standard procedure for installing many utility tools and targets verified infrastructure.
- Indirect Prompt Injection Surface: The skill describes a system for managing and installing external packages. This architectural design includes an attack surface related to the ingestion of third-party content. The documentation addresses this by detailing security controls such as audit commands and policy enforcement to manage these considerations.
- Credential Management: Instructions are provided for managing authentication tokens via environment variables or established system credential helpers. This approach avoids hardcoding secrets and follows industry best practices for secure configuration.
Audit Metadata