agentlytics-setup

Fail

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill explicitly directs the agent to request an "unsandboxed/elevated local process" and to use "sandbox_permissions: require_escalated". This instruction is intended to bypass security boundaries to allow binding to local network ports (localhost:4638).
  • [EXTERNAL_DOWNLOADS]: The skill uses npx and pnpx to download and execute the agentlytics package from a remote registry at runtime. This package is not from a recognized trusted vendor and its code is executed dynamically.
  • [COMMAND_EXECUTION]: The agent is instructed to run multiple shell commands including agentlytics --relay and agentlytics --join to manage a local server and synchronize data.
  • [DATA_EXFILTRATION]: The skill permits "broad local searches across all users" to discover usernames, project paths, and session IDs. This provides access to information outside the immediate session's context.
  • [PROMPT_INJECTION]: An indirect prompt injection surface is present. The skill ingests untrusted local data (session history and user lists) and has the capability to execute shell commands. Evidence: 1. Ingestion points: list_users and search_sessions calls in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution (npx/pnpx) in SKILL.md. 4. Sanitization: Absent.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 1, 2026, 12:52 PM
Security Audit — agent-trust-hub — agentlytics-setup