yandex-tracker
Fail
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions suggest downloading and executing a remote shell script using a dangerous pipe-to-bash pattern.
- Evidence:
curl -fsSL https://raw.githubusercontent.com/sdamarketing/tracker_mcp/main/install.sh | bashfound inSKILL.md. - Analysis: This method executes code directly from a remote source without verification or auditability, posing a significant risk if the source repository is compromised.
- [COMMAND_EXECUTION]: The skill encourages the execution of shell commands on the host system to facilitate the installation of the required MCP server.
- Evidence: The
bashinstallation block inSKILL.mddemonstrates arbitrary command execution. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it reads untrusted content from external sources and possesses significant modification permissions.
- Ingestion points: Data is ingested through tools like
get_issue,get_issue_comments, anddownload_issue_attachmentdescribed inSKILL.md. - Boundary markers: The instructions do not define boundary markers or provide guidelines to the agent for ignoring instructions that might be embedded in the Tracker issues it processes.
- Capability inventory: The skill provides a wide range of sensitive tools in
SKILL.md, includingbulk_update_issues,execute_transition,delete_issue_attachment, andupdate_entity_permissions, which could be abused if the agent follows malicious instructions hidden in Tracker data. - Sanitization: There is no mechanism described for sanitizing or validating the text and file content retrieved from the Yandex Tracker API.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/sdamarketing/tracker_mcp/main/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata