skills/quad4-software/ai/vendor-all/Gen Agent Trust Hub

vendor-all

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading assets from external URLs using wget and curl. It also suggests installing packages via npm, pnpm, or yarn. These actions are necessary for the skill's primary function of localizing remote web assets and are described as part of a manual auditing process.- [COMMAND_EXECUTION]: The skill utilizes shell commands like cp, openssl, and package managers to manage and verify local assets. These commands are standard for file management and security verification (SRI hashes).- [INDIRECT_PROMPT_INJECTION]: The skill involves processing external HTML content and remote assets, which represents a potential attack surface for instructions embedded in data. * Ingestion points: Remote URLs and HTML code analyzed by the skill. * Boundary markers: None explicitly defined in the instructions for the data being processed. * Capability inventory: Network downloads (wget, curl), file operations (cp), and package installation (npm). * Sanitization: The skill mitigates risks by recommending manual audits of remote content and the use of Subresource Integrity (SRI) hashes to verify asset integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 08:18 PM
Security Audit — agent-trust-hub — vendor-all