skills/ratacat/claude-skills/rclone/Gen Agent Trust Hub

rclone

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the official installation script from rclone.org.
  • [REMOTE_CODE_EXECUTION]: Provides commands that download and immediately execute code from a remote source via curl | bash.
  • [PRIVILEGE_ESCALATION]: Utilizes sudo to acquire root privileges for package management and script execution during installation.
  • [INDIRECT_PROMPT_INJECTION]: Processes file transfer operations which create a surface for processing instructions embedded in data or file metadata.
  • Ingestion points: Instructions for file transfers triggered by user or external data in the agent context.
  • Boundary markers: None identified in the markdown or scripts to distinguish between data and instructions.
  • Capability inventory: Access to full rclone functionality (network and file access) and shell execution capabilities for setup.
  • Sanitization: No explicit sanitization or validation of variables like file paths or remote names is performed before they are passed to the CLI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 01:28 PM
Security Audit — agent-trust-hub — rclone