skills/posit-dev/skills/r-cran-status/Gen Agent Trust Hub

r-cran-status

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches package metadata, review status, and check results from the official Comprehensive R Archive Network (CRAN) at cran.r-project.org. These requests target a well-known and authoritative service for the R programming language.
  • [COMMAND_EXECUTION]: Employs standard shell utilities including curl, grep, awk, and sed to interact with CRAN's directory structure and parse HTML responses. These operations are scoped to data retrieval and text processing.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface where user-provided inputs ({package} and {version}) are interpolated directly into shell command templates.
  • Ingestion points: User-supplied package and version strings processed in SKILL.md workflows.
  • Boundary markers: None; the shell templates do not use specific delimiters or instructions to isolate user input from the command structure.
  • Capability inventory: The skill utilizes curl, grep, awk, and sed for network interaction and parsing across multiple functions.
  • Sanitization: The workflow includes a step to strip a leading 'v' from version strings, but it lacks specific shell-escaping or validation for the package name placeholder to prevent command injection payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:07 PM