truenorth

Warn

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to include unfiltered user input directly into shell commands. Specifically, the SKILL.md and examples.md files prompt the agent to run tn ner "<user's full message>" and tn events <query>. This pattern is susceptible to command injection attacks where an adversary could include shell metacharacters (e.g., ;, &, `, $(...)) in their message to execute arbitrary code on the underlying system.
  • [EXTERNAL_DOWNLOADS]: The skill configuration specifies the global installation of the @truenorth-ai/cli@latest package from the npm registry. While this appears to be the legitimate vendor package for the TrueNorth service, all external package dependencies introduce a potential supply chain risk if the package or the registry were compromised.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — truenorth