agentar

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads an installation shell script and a package tarball from https://dtaiagtavtr-test.dl.alipaydev.com. These resources are hosted on a development domain belonging to a well-known technology service.
  • [REMOTE_CODE_EXECUTION]: The workflow involves executing a downloaded shell script (install-agentar-cli.sh) to install the agentar-cli tool on the system. This is the primary and intended function of the skill.
  • [COMMAND_EXECUTION]: The skill utilizes the agentar CLI for various tasks, including local authentication, chat interactions, and session management. These commands interact with the tool's backend to provide its core functionality.
  • [PROMPT_INJECTION]: The skill processes natural language input through the CLI (e.g., agentar "hello"), which serves as an ingestion point for user-supplied data. While this represents a surface for indirect prompt injection, the skill does not exhibit any patterns of malicious exploitation or safety boundary bypass.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 03:35 PM
Security Audit — agent-trust-hub — agentar