skills/openhands/extensions/add-skill/Gen Agent Trust Hub

add-skill

Warn

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The scripts/fetch_skill.py script retrieves the GITHUB_TOKEN environment variable and embeds it directly into the Git repository URL.
  • Evidence: repo_url = f"https://{github_token}@github.com/{owner}/{repo}.git" (line 192).
  • Usage: The URL is passed as a command-line argument to subprocess.run(['git', 'clone', ...]).
  • Risk: This practice can expose the sensitive token in system process listings (e.g., ps output) or in the tool's error output and logs if the command fails.
  • [EXTERNAL_DOWNLOADS]: The skill is designed to download content from arbitrary GitHub repositories.
  • Evidence: scripts/fetch_skill.py uses git clone and git sparse-checkout to fetch content from user-specified URLs.
  • Risk: Although targeting a well-known service, the lack of restriction on repository sources means it could be used to pull malicious code or instructions into the agent's workspace.
  • [COMMAND_EXECUTION]: The implementation relies on executing system-level git commands via subprocess.run.
  • Evidence: Multiple calls to subprocess.run are used in scripts/fetch_skill.py to perform cloning, sparse-checkout initialization, and checking out content.
  • Risk: While the script avoids direct shell injection by using list-based argument passing, it acts on parameters derived from user-supplied GitHub URLs.
  • [INDIRECT_PROMPT_INJECTION]: The skill imports SKILL.md instruction files and associated scripts from external sources into the agent's workspace.
  • Evidence: The skill fetches external files and places them in the .agents/skills/ directory for the agent to load and use.
  • Risk: This creates a significant attack surface for indirect prompt injection, as there is no validation or sanitization of the imported content, allowing malicious instructions to be integrated into the agent's operational context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 22, 2026, 09:18 AM
Security Audit — agent-trust-hub — add-skill