clui-cc-claude-overlay
Warn
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to clone and execute code from a repository (github.com/lcoutodemos/clui-cc) that is not associated with a verified organization or the stated skill author.
- [DYNAMIC_EXECUTION]: The 'Skills Marketplace' and local skill loader (~/.clui/skills/) implement dynamic loading and execution of JavaScript files. This allows for runtime code execution that bypasses static analysis.
- [INDIRECT_PROMPT_INJECTION]: The tool facilitates a multi-step chain where input from the Claude Code CLI (spawning 'claude -p') is ingested through an NDJSON stream. There are no documented boundary markers or sanitization steps for this external content, which has access to system capabilities like tool execution (e.g., bash commands).
- [PRIVILEGE_ESCALATION]: The installation guide explicitly instructs users to bypass macOS Gatekeeper security controls by using the 'Open Anyway' setting for an unsigned application bundle.
Audit Metadata