review-skill

Fail

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: Downloads and executes the Claude Code installer from the official claude.ai domain using a pipe to shell.
  • [EXTERNAL_DOWNLOADS]: Installs the skill-validator tool from an external GitHub repository (agent-ecosystem/skill-validator) using go install or Homebrew.
  • [COMMAND_EXECUTION]: Invokes several system and third-party CLI tools including skill-validator, claude, brew, and go to perform validation, scoring, and installation tasks.
  • [PRIVILEGE_ESCALATION]: Includes manual installation instructions that involve moving binaries to /usr/local/bin and applying executable permissions with chmod +x.
  • [PERSISTENCE]: Creates and updates a state configuration file at ~/.config/skill-validator/review-state.yaml to persist prerequisite check results between sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and evaluates user-provided SKILL.md and reference files, creating a potential vector for instructions embedded in those files to affect the agent's behavior or the scoring outcome.
  • Ingestion points: Reads file contents from user-specified paths in Step 4 of SKILL.md.
  • Boundary markers: No delimiters or isolation instructions are used when processing the external content.
  • Capability inventory: The ingested content is processed by skill-validator and the claude CLI tool.
  • Sanitization: The skill performs no validation or sanitization of the contents before processing.
Recommendations
  • HIGH: Downloads and executes remote code from: https://claude.ai/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 31, 2026, 04:23 PM
Security Audit — agent-trust-hub — review-skill