agentlytics-setup
Fail
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill explicitly directs the agent to request an "unsandboxed/elevated local process" and to use "sandbox_permissions: require_escalated". This instruction is intended to bypass security boundaries to allow binding to local network ports (localhost:4638).
- [EXTERNAL_DOWNLOADS]: The skill uses
npxandpnpxto download and execute theagentlyticspackage from a remote registry at runtime. This package is not from a recognized trusted vendor and its code is executed dynamically. - [COMMAND_EXECUTION]: The agent is instructed to run multiple shell commands including
agentlytics --relayandagentlytics --jointo manage a local server and synchronize data. - [DATA_EXFILTRATION]: The skill permits "broad local searches across all users" to discover usernames, project paths, and session IDs. This provides access to information outside the immediate session's context.
- [PROMPT_INJECTION]: An indirect prompt injection surface is present. The skill ingests untrusted local data (session history and user lists) and has the capability to execute shell commands. Evidence: 1. Ingestion points:
list_usersandsearch_sessionscalls in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution (npx/pnpx) in SKILL.md. 4. Sanitization: Absent.
Recommendations
- AI detected serious security threats
Audit Metadata