companion-clis
Warn
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Recommends cloning a community-developed tool (
Runpod-Network-Volume-Storage-Tool) from an unverified GitHub repository (justinwlin/Runpod-Network-Volume-Storage-Tool) for handling large volume transfers. - [EXTERNAL_DOWNLOADS]: Fetches official installation binaries and scripts for HuggingFace, Docker, and AWS CLI from established sources including
hf.co,get.docker.com, andawscli.amazonaws.com. - [REMOTE_CODE_EXECUTION]: Provides instructions to execute remote installation scripts for the HuggingFace CLI and Docker by piping
curloutput directly intobashandshrespectively. - [COMMAND_EXECUTION]: Extensively utilizes bash commands for environment setup, credential management, and cloud operations, including
ssh-keygen,ssh-add,aws,gh,hf, anddocker. - [PRIVILEGE_ESCALATION]: Includes instructions for tool installation that require
sudoon Linux and macOS, and elevated Administrator privileges forwsl --installon Windows. - [INDIRECT_PROMPT_INJECTION]: The skill acts as a surface for injection by interpolating user-provided data into shell command templates without explicit sanitization.
- Ingestion points: Network volume IDs (
NETWORK_VOLUME_ID) and file names/paths used in command templates withinreference/aws.md. - Boundary markers: No boundary markers or instructions to ignore embedded commands are present in the provided templates.
- Capability inventory: Shell execution capabilities for the HuggingFace, GitHub, Docker, and AWS CLIs as defined in the skill's allowed tools.
- Sanitization: No validation or escaping of external content is performed before interpolation into the command strings.
Audit Metadata