clui-cc-claude-overlay

Warn

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to clone and execute code from a repository (github.com/lcoutodemos/clui-cc) that is not associated with a verified organization or the stated skill author.
  • [DYNAMIC_EXECUTION]: The 'Skills Marketplace' and local skill loader (~/.clui/skills/) implement dynamic loading and execution of JavaScript files. This allows for runtime code execution that bypasses static analysis.
  • [INDIRECT_PROMPT_INJECTION]: The tool facilitates a multi-step chain where input from the Claude Code CLI (spawning 'claude -p') is ingested through an NDJSON stream. There are no documented boundary markers or sanitization steps for this external content, which has access to system capabilities like tool execution (e.g., bash commands).
  • [PRIVILEGE_ESCALATION]: The installation guide explicitly instructs users to bypass macOS Gatekeeper security controls by using the 'Open Anyway' setting for an unsigned application bundle.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 12, 2026, 08:38 PM
Security Audit — agent-trust-hub — clui-cc-claude-overlay