companion-clis

Warn

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends cloning a community-developed tool (Runpod-Network-Volume-Storage-Tool) from an unverified GitHub repository (justinwlin/Runpod-Network-Volume-Storage-Tool) for handling large volume transfers.
  • [EXTERNAL_DOWNLOADS]: Fetches official installation binaries and scripts for HuggingFace, Docker, and AWS CLI from established sources including hf.co, get.docker.com, and awscli.amazonaws.com.
  • [REMOTE_CODE_EXECUTION]: Provides instructions to execute remote installation scripts for the HuggingFace CLI and Docker by piping curl output directly into bash and sh respectively.
  • [COMMAND_EXECUTION]: Extensively utilizes bash commands for environment setup, credential management, and cloud operations, including ssh-keygen, ssh-add, aws, gh, hf, and docker.
  • [PRIVILEGE_ESCALATION]: Includes instructions for tool installation that require sudo on Linux and macOS, and elevated Administrator privileges for wsl --install on Windows.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a surface for injection by interpolating user-provided data into shell command templates without explicit sanitization.
  • Ingestion points: Network volume IDs (NETWORK_VOLUME_ID) and file names/paths used in command templates within reference/aws.md.
  • Boundary markers: No boundary markers or instructions to ignore embedded commands are present in the provided templates.
  • Capability inventory: Shell execution capabilities for the HuggingFace, GitHub, Docker, and AWS CLIs as defined in the skill's allowed tools.
  • Sanitization: No validation or escaping of external content is performed before interpolation into the command strings.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 28, 2026, 09:58 PM
Security Audit — agent-trust-hub — companion-clis