wuji-cli-upgrade

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructional guidance for using the wuji command-line utility to perform firmware updates. The operations described (such as --check, --list, and --to) are standard administrative tasks for hardware maintenance.
  • [COMMAND_EXECUTION]: The skill requires the wuji binary to be present on the system. It uses this binary to interact with connected hardware devices. This is the intended primary purpose of the skill and does not involve arbitrary or malicious shell execution.
  • [PROMPT_INJECTION]: The skill processes data from external sources, specifically firmware release notes and device metadata retrieved via the wuji tool. While this represents a surface for indirect prompt injection, the skill includes documentation on safety semantics (confirmation prompts) and does not provide the agent with high-risk autonomous capabilities that would facilitate an attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 04:25 AM
Security Audit — agent-trust-hub — wuji-cli-upgrade