cli-review-runner

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's primary function is to audit command-line tools by executing them. It invokes the user-provided target CLI with various flags (e.g., --help, --version) and bogus arguments to test error handling and output format.\n
  • Evidence: scripts/lib/common.sh contains the crr_capture function which executes the target command.\n
  • Safety Measures: The skill uses crr_with_timeout to limit execution to 5 seconds by default and redirects stdin from /dev/null to prevent the agent from hanging on interactive prompts.\n\n- [DYNAMIC_EXECUTION]: The skill uses a Perl one-liner to implement a portable timeout mechanism on systems (like macOS) that lack GNU Coreutils.\n
  • Evidence: scripts/lib/common.sh uses perl -e 'alarm shift; exec @ARGV' to wrap command execution.\n\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes the output of the audited CLI tools. The resulting audit report includes fragments of this output (as 'evidence'), which creates a potential surface for indirect prompt injection if a malicious CLI tool is audited.\n
  • Ingestion Points: scripts/lib/common.sh (via crr_capture) and scripts/lib/probes.sh (via grep and redirection).\n
  • Capability Inventory: The skill can execute local binaries and write findings to temporary files.\n
  • Boundary Markers: Findings are encapsulated in a structured report format (JSON/NDJSON/Table) created by scripts/render.sh.\n
  • Sanitization: scripts/lib/common.sh includes a crr_json_escape function to sanitize string values before including them in the NDJSON findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:48 AM
Security Audit — agent-trust-hub — cli-review-runner