done-or-not

Fail

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides an installation method that fetches a shell script from the author's GitHub repository.
  • [REMOTE_CODE_EXECUTION]: The skill includes a one-liner installer that pipes a remote script directly to a shell interpreter (curl -fsSL ... | sh). The script is hosted under the author's personal GitHub namespace.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates a surface for indirect prompt injection by ingesting and presenting the full output of verifying commands to the agent.
  • Ingestion points: Full command output and receipt data are processed by the agent (SKILL.md).
  • Boundary markers: While the skill uses SHA-256 hashing for tamper-evidence of the receipt, it does not specify the use of delimiters or isolation markers to distinguish command output from agent instructions.
  • Capability inventory: The skill enables the execution of arbitrary shell commands (e.g., tests, build, lint, curl) as part of the verification process (SKILL.md).
  • Sanitization: The skill does not describe mechanisms for sanitizing or escaping the captured output before it is returned to the agent's context.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/mohamedzhioua/agent-done-or-not/main/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 17, 2026, 01:20 AM
Security Audit — agent-trust-hub — done-or-not