cli-review-runner
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's primary function is to audit command-line tools by executing them. It invokes the user-provided target CLI with various flags (e.g.,
--help,--version) and bogus arguments to test error handling and output format.\n - Evidence:
scripts/lib/common.shcontains thecrr_capturefunction which executes the target command.\n - Safety Measures: The skill uses
crr_with_timeoutto limit execution to 5 seconds by default and redirects stdin from/dev/nullto prevent the agent from hanging on interactive prompts.\n\n- [DYNAMIC_EXECUTION]: The skill uses a Perl one-liner to implement a portable timeout mechanism on systems (like macOS) that lack GNU Coreutils.\n - Evidence:
scripts/lib/common.shusesperl -e 'alarm shift; exec @ARGV'to wrap command execution.\n\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes the output of the audited CLI tools. The resulting audit report includes fragments of this output (as 'evidence'), which creates a potential surface for indirect prompt injection if a malicious CLI tool is audited.\n - Ingestion Points:
scripts/lib/common.sh(viacrr_capture) andscripts/lib/probes.sh(viagrepand redirection).\n - Capability Inventory: The skill can execute local binaries and write findings to temporary files.\n
- Boundary Markers: Findings are encapsulated in a structured report format (JSON/NDJSON/Table) created by
scripts/render.sh.\n - Sanitization:
scripts/lib/common.shincludes acrr_json_escapefunction to sanitize string values before including them in the NDJSON findings.
Audit Metadata