done-or-not
Fail
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation provides an installation method that fetches a shell script from the author's GitHub repository.
- [REMOTE_CODE_EXECUTION]: The skill includes a one-liner installer that pipes a remote script directly to a shell interpreter (
curl -fsSL ... | sh). The script is hosted under the author's personal GitHub namespace. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates a surface for indirect prompt injection by ingesting and presenting the full output of verifying commands to the agent.
- Ingestion points: Full command output and receipt data are processed by the agent (SKILL.md).
- Boundary markers: While the skill uses SHA-256 hashing for tamper-evidence of the receipt, it does not specify the use of delimiters or isolation markers to distinguish command output from agent instructions.
- Capability inventory: The skill enables the execution of arbitrary shell commands (e.g., tests, build, lint, curl) as part of the verification process (SKILL.md).
- Sanitization: The skill does not describe mechanisms for sanitizing or escaping the captured output before it is returned to the agent's context.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/mohamedzhioua/agent-done-or-not/main/install.sh - DO NOT USE without thorough review
Audit Metadata