skills/ruvnet/ruflo/iot-register/Gen Agent Trust Hub

iot-register

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses npx to fetch and execute the @claude-flow/plugin-iot-cognitum package directly from the npm registry. By specifying the @latest tag, the skill downloads the most recent version of the code at runtime and executes it immediately, which is a significant execution risk if the remote package is compromised.
  • [EXTERNAL_DOWNLOADS]: The skill relies on external code that is not from a recognized trusted vendor and does not pin a specific version or provide a hash for integrity verification, introducing a supply chain risk.
  • [COMMAND_EXECUTION]: The skill executes shell commands via npx. User-provided inputs for endpoint and token are interpolated directly into these commands, which could lead to command injection if the agent or the CLI tool does not sufficiently sanitize the inputs.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data inputs that could contain malicious instructions.
  • Ingestion points: The endpoint and token arguments are provided by the user and processed in the skill instructions.
  • Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to treat these inputs as data rather than instructions.
  • Capability inventory: The skill has access to the Bash tool for command execution and a memory_store tool for data persistence.
  • Sanitization: There is no evidence of sanitization or validation of the input strings before they are used in shell commands or stored in memory.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 11:38 AM
Security Audit — agent-trust-hub — iot-register