skills/ortus-boxlang/skills/bx-oshi/Gen Agent Trust Hub

bx-oshi

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface by ingesting data from the host operating system, such as process names (os.getProcesses()), disk identifiers, and network interface names. This untrusted content is pulled into the agent's context without explicit boundary markers or sanitization logic in the provided patterns.
  • [COMMAND_EXECUTION]: The skill documentation guides users to install the bx-oshi module using standard package management tools like install-bx-module and box install. These commands are standard for extending the vendor's runtime with the necessary telemetry capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:01 AM
Security Audit — agent-trust-hub — bx-oshi