truenorth
Warn
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to include unfiltered user input directly into shell commands. Specifically, the
SKILL.mdandexamples.mdfiles prompt the agent to runtn ner "<user's full message>"andtn events <query>. This pattern is susceptible to command injection attacks where an adversary could include shell metacharacters (e.g.,;,&,`,$(...)) in their message to execute arbitrary code on the underlying system. - [EXTERNAL_DOWNLOADS]: The skill configuration specifies the global installation of the
@truenorth-ai/cli@latestpackage from the npm registry. While this appears to be the legitimate vendor package for the TrueNorth service, all external package dependencies introduce a potential supply chain risk if the package or the registry were compromised.
Audit Metadata