cli-tools
Fail
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONMETADATA_POISONING
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill makes extensive use of
sudoacross its orchestration and installation scripts, posing a risk of unauthorized privilege acquisition if not monitored. scripts/auto_update.shusessudoforapt-get update,apt-get upgrade, andsnap refreshoperations.scripts/installers/package_manager.shutilizessudoforapt-get,dnf, andpacmanpackage installations.scripts/install_composer.shexecutessudo cpandsudo chmodif the user lacks write access to the/usr/local/bindirectory.scripts/lib/install_strategy.shdefinesINSTALLassudo installwhen the target prefix is global.- [PERSISTENCE]: The skill implements automated modifications to user shell profiles, which is a common persistence mechanism.
scripts/lib/path_check.shidentifies and appends PATH exports and initialization hooks to.bashrc,.zshrc,.profile, and.config/fish/config.fishvia theadd_to_shell_rcandadd_shell_hookfunctions.- It installs a helper function
_eval_ifinto RC files, which facilitates the persistence ofevalhooks for tools likestarship,zoxide, anddirenv. - [DYNAMIC_EXECUTION]: The skill executes arbitrary strings defined in catalog metadata.
scripts/installers/package_manager.shusesbash -c "$cmd"to runversion_commandstrings parsed from JSON catalog files. While it uses an allowlist for binaries, it still executes dynamic logic defined outside the script.scripts/installers/dedicated_script.shexecutes scripts by name provided in the catalog files viaexec "$SCRIPT_PATH".- [REMOTE_CODE_EXECUTION]: Several installers download and execute code from remote sources.
scripts/installers/aws_installer.shdownloads a zip from a catalog-defined URL and executes the./aws/installscript.scripts/install_composer.shdownloadscomposer.pharfromgetcomposer.organd executes it withphpto verify the version.scripts/installers/github_release_binary.shdownloads and executes binaries from GitHub and GitLab releases.- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to manipulation through project files.
- Ingestion points:
scripts/detect_project_type.shscans the project directory for files such aspackage.json,Gemfile, andpyproject.tomlto determine tool requirements. - Capability inventory: The skill has the capability to write to the filesystem (RC files), execute shell commands with
sudo, and download external scripts. - Sanitization: There is no validation or sanitization of the content of these untrusted project files before they influence the agent's environment audit and installation recommendations.
- [METADATA_POISONING]: The skill relies on metadata files (catalog JSONs) to define installation methods, scripts, and version commands. If these catalog files are manipulated, the skill will execute malicious instructions.
- [EXTERNAL_DOWNLOADS]: The skill regularly fetches assets from external domains including
github.com,gitlab.com,releases.hashicorp.com,getcomposer.org, and AWS S3 buckets.
Recommendations
- AI detected serious security threats
Audit Metadata