clojure-expert
Fail
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill in
references/EXAMPLES.mdinstructs the user or agent to download installation scripts and binaries from external URLs:https://download.clojure.org/install/linux-install-1.11.1.1435.shandhttps://raw.githubusercontent.com/technomancy/leiningen/stable/bin/lein. These sources are not within the explicitly trusted organization list. - [REMOTE_CODE_EXECUTION]: The skill demonstrates a high-risk pattern of downloading remote scripts followed by immediate execution (
curl ... && chmod +x ... && ./...), which facilitates the execution of arbitrary remote content. - [PRIVILEGE_ESCALATION]: The installation examples utilize
sudoto execute downloaded shell scripts and to move binaries into system-protected directories such as/usr/local/bin/, granting the external content administrative permissions on the system. - [COMMAND_EXECUTION]: The skill is configured with the
Bashtool and provides commands to install software, modify system paths, and write configuration files (e.g.,deps.edn) directly to the filesystem.
Recommendations
- AI detected serious security threats
Audit Metadata