penetration-testing-with-strix
Fail
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill suggests installing the Strix agent by piping a remote script directly to the bash shell:
curl -sSL https://strix.ai/install | bash. This pattern is highly risky as it executes remote code from an external source with the user's current privileges, bypassing package manager security checks and signature verification. - [COMMAND_EXECUTION]: The skill facilitates the execution of the
strixCLI, which performs complex operations including Docker container management and automated security scanning of local and remote targets. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze and exploit vulnerabilities in external targets, which creates a significant attack surface for indirect prompt injection if those targets contain malicious instructions.
- Ingestion points: Target URLs, public git repositories, and local code directories provided through the
-tor--target-listflags. - Boundary markers: The skill's instructions do not include boundary markers or guidance for the agent to ignore instructions found within target data.
- Capability inventory: The
strixtool has extensive capabilities, including network communication and the ability to modify files in the local workspace when a local path is mounted into its sandbox. - Sanitization: There is no mention of sanitization or filtering logic applied to the content retrieved from the targets before it is processed by the AI agents.
Recommendations
- HIGH: Downloads and executes remote code from: https://strix.ai/install - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata