cli-tools

Fail

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: HIGHPRIVILEGE_ESCALATIONPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONMETADATA_POISONING
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill makes extensive use of sudo across its orchestration and installation scripts, posing a risk of unauthorized privilege acquisition if not monitored.
  • scripts/auto_update.sh uses sudo for apt-get update, apt-get upgrade, and snap refresh operations.
  • scripts/installers/package_manager.sh utilizes sudo for apt-get, dnf, and pacman package installations.
  • scripts/install_composer.sh executes sudo cp and sudo chmod if the user lacks write access to the /usr/local/bin directory.
  • scripts/lib/install_strategy.sh defines INSTALL as sudo install when the target prefix is global.
  • [PERSISTENCE]: The skill implements automated modifications to user shell profiles, which is a common persistence mechanism.
  • scripts/lib/path_check.sh identifies and appends PATH exports and initialization hooks to .bashrc, .zshrc, .profile, and .config/fish/config.fish via the add_to_shell_rc and add_shell_hook functions.
  • It installs a helper function _eval_if into RC files, which facilitates the persistence of eval hooks for tools like starship, zoxide, and direnv.
  • [DYNAMIC_EXECUTION]: The skill executes arbitrary strings defined in catalog metadata.
  • scripts/installers/package_manager.sh uses bash -c "$cmd" to run version_command strings parsed from JSON catalog files. While it uses an allowlist for binaries, it still executes dynamic logic defined outside the script.
  • scripts/installers/dedicated_script.sh executes scripts by name provided in the catalog files via exec "$SCRIPT_PATH".
  • [REMOTE_CODE_EXECUTION]: Several installers download and execute code from remote sources.
  • scripts/installers/aws_installer.sh downloads a zip from a catalog-defined URL and executes the ./aws/install script.
  • scripts/install_composer.sh downloads composer.phar from getcomposer.org and executes it with php to verify the version.
  • scripts/installers/github_release_binary.sh downloads and executes binaries from GitHub and GitLab releases.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to manipulation through project files.
  • Ingestion points: scripts/detect_project_type.sh scans the project directory for files such as package.json, Gemfile, and pyproject.toml to determine tool requirements.
  • Capability inventory: The skill has the capability to write to the filesystem (RC files), execute shell commands with sudo, and download external scripts.
  • Sanitization: There is no validation or sanitization of the content of these untrusted project files before they influence the agent's environment audit and installation recommendations.
  • [METADATA_POISONING]: The skill relies on metadata files (catalog JSONs) to define installation methods, scripts, and version commands. If these catalog files are manipulated, the skill will execute malicious instructions.
  • [EXTERNAL_DOWNLOADS]: The skill regularly fetches assets from external domains including github.com, gitlab.com, releases.hashicorp.com, getcomposer.org, and AWS S3 buckets.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 19, 2026, 05:34 PM