review-with-dora

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx to fetch the @hacksmith/doraval package from the NPM registry if the tool is not found locally. It also employs dora harness apply to download configuration files and kit origins from GitHub repositories.
  • [REMOTE_CODE_EXECUTION]: The instructions utilize npx to download and execute code from a remote package registry as a fallback installation method.
  • [COMMAND_EXECUTION]: The skill makes extensive use of CLI tools (dora, hermes) to perform file operations, environment setup, and routine execution.
  • [PERSISTENCE]: The dora harness suite of commands establishes persistence by creating cron jobs to run routines at specified intervals and installing hooks that interact with external services like GitHub and Slack.
  • [CREDENTIALS_UNSAFE]: The skill manages authentication through dora config set identity.api_key. The documentation follows security best practices by directing users to the official vendor domain for key generation and advising against echoing sensitive tokens.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data by reviewing and fixing external SKILL.md and configuration files.
  • Ingestion points: Files are processed using dora review, dora fix, and dora scan.
  • Boundary markers: The instructions do not define specific delimiters or ignore instructions for the content being processed.
  • Capability inventory: The tool possesses the ability to modify the filesystem, execute code via npx, and establish persistence via cron.
  • Sanitization: No specific sanitization or validation steps for the content of the processed files are mentioned.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 06:47 AM
Security Audit — agent-trust-hub — review-with-dora