skills/rivet-dev/skills/rivet-agentos/Gen Agent Trust Hub

rivet-agentos

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill contains numerous examples demonstrating how to run shell commands and manage processes within isolated virtual machines.
  • Example scripts such as examples/host-functions/guest.py and examples/processes/exec.ts use system calls like subprocess.run and process.exec to demonstrate interaction with the VM environment.
  • The browse CLI skill example provides a management interface for browser automation via shell commands.
  • [DYNAMIC_EXECUTION]: The platform's ability to execute code at runtime is a primary focus of the examples.
  • Multiple examples in examples/js-quickstart/ and examples/python-quickstart/ use evaluate() and execute() methods to run JavaScript and Python logic inside the guest environment.
  • The TypeScript example demonstrates checking and transpiling code before execution to ensure validity.
  • [EXTERNAL_DOWNLOADS]: The documentation provides instructions for setting up the environment using standard package managers.
  • Setup steps include npm install and npx for installing the agentOS SDK and auxiliary tools like the browse CLI.
  • The browse skill includes functionality to discover and install additional site-specific automation skills from the browse.sh catalog.
  • [INDIRECT_PROMPT_INJECTION]: Several examples involve fetching and processing external web data, which introduces a potential surface for indirect prompt injection.
  • Ingestion points: External web content is retrieved using browse cloud fetch in the examples/browserbase/ integration.
  • Boundary markers: The provided examples do not explicitly demonstrate the use of delimiters or 'ignore' instructions when processing fetched data.
  • Capability inventory: The skill documentation shows that the environment has full capabilities for file system operations, networking, and process execution.
  • Sanitization: The examples focus on the mechanics of fetching data rather than the security best practices of sanitizing untrusted input before prompt interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 02:00 PM
Security Audit — agent-trust-hub — rivet-agentos