shell-integration

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documents common installation script patterns that use curl or wget to fetch binaries from external sources.
  • Evidence: references/plugin-distribution.md contains a template for downloading a binary from a GitHub repository using curl -fsSL "$url" -o "${BIN_DIR}/mytool".
  • [REMOTE_CODE_EXECUTION]: Patterns for dynamic shell integration are provided, which involve executing code generated by external binaries.
  • Evidence: references/plugin-distribution.md demonstrates the eval "$(mytool init zsh)" pattern common in modern CLI utilities to set up environment hooks and completions at shell startup.
  • [COMMAND_EXECUTION]: Illustrative examples of Inter-Process Communication (IPC) using socat are included.
  • Evidence: references/posix-scripting.md includes a socat listener example (socat UNIX-LISTEN:/tmp/myapp.sock,fork EXEC:./handler.sh) used to demonstrate Unix socket communication. While flagged as a potential reverse shell pattern by automated scanners, it is a legitimate IPC pattern within the context of the documentation.
  • [PERSISTENCE]: The skill describes methods for modifying shell initialization files to maintain plugin functionality across sessions.
  • Evidence: references/plugin-distribution.md contains functions like add_to_shell_config and install_to_shell that append initialization logic to .bashrc, .zshrc, and Fish configuration directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents hooks that process command-line input and shell events, creating a potential surface for indirect prompt injection if an agent interacts with untrusted inputs through these patterns.
  • Ingestion points: Shell events and command strings are ingested via PROMPT_COMMAND (Bash), preexec/precmd hooks (Zsh), and event handlers (Fish) as shown in references/bash-integration.md, references/zsh-integration.md, and references/fish-integration.md.
  • Boundary markers: The provided examples do not include explicit delimiter-based boundary markers or instructions to ignore embedded commands in the processed data.
  • Capability inventory: The skill demonstrates capabilities for file writing (references/plugin-distribution.md), network operations (references/plugin-distribution.md), and subprocess execution (references/posix-scripting.md).
  • Sanitization: The documentation focuses on functional implementation and does not demonstrate specific sanitization or escaping of external command content to prevent injection.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:51 AM
Security Audit — agent-trust-hub — shell-integration