godmode-runtime
Fail
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The primary instructions in
SKILL.mdsuggest locating thegodmode_cli.pyexecutable using a broad search command:find ~ -maxdepth 5 -name 'godmode_cli.py'. This approach is non-deterministic and creates a path hijacking risk where a malicious script with the same name placed in a user-accessible directory (such as~/Downloads) could be selected and executed viapython3. - [COMMAND_EXECUTION]: The documentation recommends persisting this
findcommand in shell configuration files (~/.zshrcor~/.bashrc), causing the potentially unsafe search to execute every time a terminal session is initiated. - [EXTERNAL_DOWNLOADS]: The skill's setup instructions require cloning an external repository from
https://github.com/ronjunevaldoz/godmode.gitand installing dependencies viapip install -r requirements.txt. While associated with the skill author, these actions involve the execution of unverified external code. - [DATA_EXFILTRATION]: The
scripts/health_check.pyutility automatically performs a network request to theOLLAMA_BASE_URLusing therequestslibrary. This functionality could be leveraged to probe internal network infrastructure or signal environment details to a remote server. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes local file content provided via the
--fileflag during routing. - Ingestion points: Content of local files passed to
godmode_cli.pyas arguments. - Boundary markers: There are no explicit delimiters or instructions to ignore instructions embedded within the interpolated file content described in the routing examples.
- Capability inventory: The skill environment allows for shell command execution and interaction with various cloud-based AI service APIs.
- Sanitization: The analysis did not identify any mechanisms for validating or sanitizing the content of the files before they are processed by the routing pipeline.
Recommendations
- AI detected serious security threats
Audit Metadata