openhue

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download a pre-built binary directly from a community GitHub repository (openhue/openhue-cli) and install it to the local system. While this repository is specific to the tool's functionality, it is not an officially verified vendor on the trusted list, representing a supply chain risk.
  • [COMMAND_EXECUTION]: The skill relies on the execution of the openhue command-line interface to perform all its functions. The AI agent is instructed to construct and run shell commands, which increases the potential attack surface.
  • [INDIRECT_PROMPT_INJECTION]: The skill lacks sanitization and boundary markers for user-provided data, creating a vulnerability where malicious inputs could be interpolated into shell commands.
  • Ingestion points: Natural language requests containing light, room, or scene names.
  • Boundary markers: Absent; there are no instructions to delimit or escape user input when generating commands.
  • Capability inventory: Shell command execution via the openhue binary.
  • Sanitization: None identified; the skill directly maps user input to command arguments.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 04:03 PM