jobs-track

Fail

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute installation scripts for the sjctl utility directly from the vendor's official GitHub repository.- Evidence: curl -fsSL https://raw.githubusercontent.com/solid-company/solid-jobs-skills/v0.6.0/scripts/install-sjctl.sh | bash- Evidence: irm https://raw.githubusercontent.com/solid-company/solid-jobs-skills/v0.6.0/scripts/install-sjctl.ps1 | iex- [COMMAND_EXECUTION]: The primary functionality of the skill relies on executing local shell commands via the sjctl utility to manage the job pipeline.- [INDIRECT_PROMPT_INJECTION]: The skill processes data returned from tool execution, such as job titles and notes, which represents a potential injection surface if the tracked data contains malicious instructions.- Ingestion points: Results from sjctl track list --json.- Boundary markers: None.- Capability inventory: Local command execution (sjctl).- Sanitization: No sanitization or validation of the ingested JSON content is specified.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/solid-company/solid-jobs-skills/v0.6.0/scripts/install-sjctl.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 14, 2026, 08:15 AM
Security Audit — agent-trust-hub — jobs-track