iot-register
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill uses
npxto fetch and execute the@claude-flow/plugin-iot-cognitumpackage directly from the npm registry. By specifying the@latesttag, the skill downloads the most recent version of the code at runtime and executes it immediately, which is a significant execution risk if the remote package is compromised. - [EXTERNAL_DOWNLOADS]: The skill relies on external code that is not from a recognized trusted vendor and does not pin a specific version or provide a hash for integrity verification, introducing a supply chain risk.
- [COMMAND_EXECUTION]: The skill executes shell commands via
npx. User-provided inputs forendpointandtokenare interpolated directly into these commands, which could lead to command injection if the agent or the CLI tool does not sufficiently sanitize the inputs. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data inputs that could contain malicious instructions.
- Ingestion points: The
endpointandtokenarguments are provided by the user and processed in the skill instructions. - Boundary markers: The skill lacks explicit boundary markers or instructions to the agent to treat these inputs as data rather than instructions.
- Capability inventory: The skill has access to the
Bashtool for command execution and amemory_storetool for data persistence. - Sanitization: There is no evidence of sanitization or validation of the input strings before they are used in shell commands or stored in memory.
Recommendations
- AI detected serious security threats
Audit Metadata