agentar
Fail
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions to download an installation script from 'https://dtaiagtavtr.antdigital.com/agentar-cli/install.sh' and pipe its content directly into the 'bash' shell. This method allows for the immediate execution of remote code without prior validation or security review.- [EXTERNAL_DOWNLOADS]: The skill references and downloads several external artifacts, including an installation script, a CLI binary, and a skill archive ('skill.zip') from the domain 'dtaiagtavtr.antdigital.com'. It also utilizes the 'npx skills add' command to fetch additional platform components.- [COMMAND_EXECUTION]: The skill instructs the agent to perform multiple command-line operations, including environment verification ('node -v', 'npm -v'), path modification ('export PATH'), and extensive use of the 'agentar' CLI for authentication, chat sessions, and agent delegation.
Recommendations
- HIGH: Downloads and executes remote code from: https://dtaiagtavtr.antdigital.com/agentar-cli/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata