setup-boltz-remote-tool

Fail

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches a remote Python wheel from https://connect.aiscientist.tools/. The source domain is not recognized as a trusted service or vendor resource.\n- [REMOTE_CODE_EXECUTION]: Installs an external package directly from a URL via pip install, facilitating the execution of remote code. Although a SHA-256 integrity hash is provided, the remote source is unverified.\n- [COMMAND_EXECUTION]: The skill instructs the user to execute various shell commands, including pip install, python scripts/remote_validation/setup_skill_preflight.py, and ToolUniverse CLI operations (tu remote login, tu serve), to deploy the Boltz tool.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 24, 2026, 08:20 AM
Security Audit — agent-trust-hub — setup-boltz-remote-tool