clojure-expert

Fail

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill in references/EXAMPLES.md instructs the user or agent to download installation scripts and binaries from external URLs: https://download.clojure.org/install/linux-install-1.11.1.1435.sh and https://raw.githubusercontent.com/technomancy/leiningen/stable/bin/lein. These sources are not within the explicitly trusted organization list.
  • [REMOTE_CODE_EXECUTION]: The skill demonstrates a high-risk pattern of downloading remote scripts followed by immediate execution (curl ... && chmod +x ... && ./...), which facilitates the execution of arbitrary remote content.
  • [PRIVILEGE_ESCALATION]: The installation examples utilize sudo to execute downloaded shell scripts and to move binaries into system-protected directories such as /usr/local/bin/, granting the external content administrative permissions on the system.
  • [COMMAND_EXECUTION]: The skill is configured with the Bash tool and provides commands to install software, modify system paths, and write configuration files (e.g., deps.edn) directly to the filesystem.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — clojure-expert