clerk-backend-api

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The instructions in SKILL.md for fetching tags and endpoint details directly interpolate user-controlled variables (e.g., ${version_name}, ${path}, ${method}, ${tag_name}) into shell commands involving curl, bash, and node. If the agent incorporates unsanitized user input into these commands, an attacker could execute arbitrary code via command injection (e.g., by providing a version string like 2024-01-01; id;).
  • [EXTERNAL_DOWNLOADS]: The skill fetches OpenAPI specifications and version lists from a public GitHub repository (clerk/openapi-specs). While the source is a known service provider, downloading and processing external files at runtime introduces a dependency on the integrity of the remote repository.
  • [DYNAMIC_EXECUTION]: Several utility scripts (scripts/extract-tag-endpoints.sh and scripts/extract-endpoint-detail.sh) use `node
  • <<'SCRIPT'` to execute embedded JavaScript code blocks. This dynamic execution is used to parse the YAML specification data downloaded from GitHub.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from an external repository to generate agent context and endpoint descriptions. This presents an indirect injection surface where a compromise of the source files could be used to influence the agent's behavior.
  • Ingestion points: Specification downloads in SKILL.md (Steps 1, 2, and 3) and the scripts/api-specs-context.sh script.
  • Boundary markers: None; the external content is processed and presented directly.
  • Capability inventory: The skill has access to shell execution (Bash), network operations (WebFetch, curl), and file system reads.
  • Sanitization: Processing is limited to regex-based extraction and basic string manipulation in helper scripts.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/clerk/openapi-specs/main/bapi/${version_name} - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — clerk-backend-api