windows-rescue-from-linux

Fail

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill downloads and executes scripts for installing Node.js and the Node Version Manager (NVM). These resources are hosted on well-known and official domains (deb.nodesource.com and raw.githubusercontent.com), which are standard in professional development environments.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of numerous recovery packages and AI agent software from official repositories, including the Ubuntu apt repositories and the npm registry.
  • [COMMAND_EXECUTION]: The skill requires and utilizes broad administrative permissions to execute shell commands. This capability is essential for performing system-level repairs such as mounting disks, editing registries, and reconfiguring boot loaders.
  • [PROMPT_INJECTION]: The skill processes data from external sources that could contain malicious instructions designed to influence the AI agent's behavior (Indirect Prompt Injection). * Ingestion points: Windows registry files (SYSTEM, SOFTWARE, SAM, NTUSER.DAT), event logs (.evtx), and system configuration files (pending.xml, hosts) in the target filesystem. * Boundary markers: None. The skill does not use specific delimiters to separate untrusted data from agent instructions. * Capability inventory: The skill has the ability to execute shell commands, write to the filesystem, and modify registry entries. * Sanitization: No evidence of data sanitization or validation for the content read from the Windows system was found.
Recommendations
  • HIGH: Downloads and executes remote code from: https://deb.nodesource.com/setup_20.x - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 29, 2026, 11:51 AM
Security Audit — agent-trust-hub — windows-rescue-from-linux