xerg
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the latest version of the @xerg/cli utility from the NPM registry and retrieves setup instructions from the vendor's official domain at xerg.ai. It also utilizes tools like ssh and rsync to pull logs from remote hosts when requested by the user.\n- [DATA_EXPOSURE]: Accesses sensitive local files, including agent transcripts, log files, and databases such as ~/.hermes/state.db, to perform monetary audits of AI token usage.\n- [COMMAND_EXECUTION]: Executes shell commands via npx to run the audit tool locally. The skill includes instructions to ensure commands are executed with shell-safe quoting.\n- [INDIRECT_PROMPT_INJECTION]: \n
- Ingestion points: The skill processes external data sources including OpenClaw logs, Hermes state databases, and Claude Code transcripts.\n
- Boundary markers: Instructions explicitly mandate that the agent must request user permission before reading any local data or performing installations.\n
- Capability inventory: The skill has the capability to execute shell commands, read local files, and transmit audit metadata to the vendor's cloud service.\n
- Sanitization: The agent is instructed to use structured JSON output and shell-safe quoting to mitigate risks from potentially malicious log content.
Audit Metadata