shell-integration
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents common installation script patterns that use
curlorwgetto fetch binaries from external sources. - Evidence:
references/plugin-distribution.mdcontains a template for downloading a binary from a GitHub repository usingcurl -fsSL "$url" -o "${BIN_DIR}/mytool". - [REMOTE_CODE_EXECUTION]: Patterns for dynamic shell integration are provided, which involve executing code generated by external binaries.
- Evidence:
references/plugin-distribution.mddemonstrates theeval "$(mytool init zsh)"pattern common in modern CLI utilities to set up environment hooks and completions at shell startup. - [COMMAND_EXECUTION]: Illustrative examples of Inter-Process Communication (IPC) using
socatare included. - Evidence:
references/posix-scripting.mdincludes asocatlistener example (socat UNIX-LISTEN:/tmp/myapp.sock,fork EXEC:./handler.sh) used to demonstrate Unix socket communication. While flagged as a potential reverse shell pattern by automated scanners, it is a legitimate IPC pattern within the context of the documentation. - [PERSISTENCE]: The skill describes methods for modifying shell initialization files to maintain plugin functionality across sessions.
- Evidence:
references/plugin-distribution.mdcontains functions likeadd_to_shell_configandinstall_to_shellthat append initialization logic to.bashrc,.zshrc, and Fish configuration directories. - [INDIRECT_PROMPT_INJECTION]: The skill documents hooks that process command-line input and shell events, creating a potential surface for indirect prompt injection if an agent interacts with untrusted inputs through these patterns.
- Ingestion points: Shell events and command strings are ingested via
PROMPT_COMMAND(Bash),preexec/precmdhooks (Zsh), and event handlers (Fish) as shown inreferences/bash-integration.md,references/zsh-integration.md, andreferences/fish-integration.md. - Boundary markers: The provided examples do not include explicit delimiter-based boundary markers or instructions to ignore embedded commands in the processed data.
- Capability inventory: The skill demonstrates capabilities for file writing (
references/plugin-distribution.md), network operations (references/plugin-distribution.md), and subprocess execution (references/posix-scripting.md). - Sanitization: The documentation focuses on functional implementation and does not demonstrate specific sanitization or escaping of external command content to prevent injection.
Audit Metadata