clerk-backend-api
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions in SKILL.md for fetching tags and endpoint details directly interpolate user-controlled variables (e.g.,
${version_name},${path},${method},${tag_name}) into shell commands involvingcurl,bash, andnode. If the agent incorporates unsanitized user input into these commands, an attacker could execute arbitrary code via command injection (e.g., by providing a version string like2024-01-01; id;). - [EXTERNAL_DOWNLOADS]: The skill fetches OpenAPI specifications and version lists from a public GitHub repository (
clerk/openapi-specs). While the source is a known service provider, downloading and processing external files at runtime introduces a dependency on the integrity of the remote repository. - [DYNAMIC_EXECUTION]: Several utility scripts (
scripts/extract-tag-endpoints.shandscripts/extract-endpoint-detail.sh) use `node - <<'SCRIPT'` to execute embedded JavaScript code blocks. This dynamic execution is used to parse the YAML specification data downloaded from GitHub.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from an external repository to generate agent context and endpoint descriptions. This presents an indirect injection surface where a compromise of the source files could be used to influence the agent's behavior.
- Ingestion points: Specification downloads in SKILL.md (Steps 1, 2, and 3) and the
scripts/api-specs-context.shscript. - Boundary markers: None; the external content is processed and presented directly.
- Capability inventory: The skill has access to shell execution (
Bash), network operations (WebFetch,curl), and file system reads. - Sanitization: Processing is limited to regex-based extraction and basic string manipulation in helper scripts.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/clerk/openapi-specs/main/bapi/${version_name} - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata