review-skill
Fail
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Downloads and executes the Claude Code installer from the official
claude.aidomain using a pipe to shell. - [EXTERNAL_DOWNLOADS]: Installs the
skill-validatortool from an external GitHub repository (agent-ecosystem/skill-validator) usinggo installor Homebrew. - [COMMAND_EXECUTION]: Invokes several system and third-party CLI tools including
skill-validator,claude,brew, andgoto perform validation, scoring, and installation tasks. - [PRIVILEGE_ESCALATION]: Includes manual installation instructions that involve moving binaries to
/usr/local/binand applying executable permissions withchmod +x. - [PERSISTENCE]: Creates and updates a state configuration file at
~/.config/skill-validator/review-state.yamlto persist prerequisite check results between sessions. - [INDIRECT_PROMPT_INJECTION]: The skill reads and evaluates user-provided
SKILL.mdand reference files, creating a potential vector for instructions embedded in those files to affect the agent's behavior or the scoring outcome. - Ingestion points: Reads file contents from user-specified paths in Step 4 of SKILL.md.
- Boundary markers: No delimiters or isolation instructions are used when processing the external content.
- Capability inventory: The ingested content is processed by
skill-validatorand theclaudeCLI tool. - Sanitization: The skill performs no validation or sanitization of the contents before processing.
Recommendations
- HIGH: Downloads and executes remote code from: https://claude.ai/install.sh - DO NOT USE without thorough review
Audit Metadata