agency-stack

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using bash to verify the presence of tool suites. Specifically, it uses test -f to check for SKILL.md files and find piped to wc -l to count sub-skills in local directories (~/.claude/skills/). This behavior is consistent with its stated purpose of status checking.
  • [REMOTE_CODE_EXECUTION]: The skill contains multiple pre-formatted shell commands that download scripts and pipe them directly into bash (e.g., curl -sL https://raw.githubusercontent.com/zubair-trabzada/ai-marketing-claude/main/install.sh | bash). Although the instructions specify displaying these commands to the user rather than the agent executing them automatically, the use of the curl | bash pattern from external sources is a high-risk installation method. Note: The resources are hosted by the skill's author (zubair-trabzada).
  • [INDIRECT_PROMPT_INJECTION]: The skill parses data from local files, including VERSION files and metadata from SKILL.md, to generate its status report. This creates an attack surface where a compromised or malicious tool suite could influence the agent's behavior by embedding instructions in these files.
  • Ingestion points: Reads VERSION, SKILL.md, package.json, and metadata.json from suite directories.
  • Boundary markers: None (the skill simply displays the extracted information).
  • Capability inventory: File system discovery via find and command execution via bash for status checking.
  • Sanitization: None (extracted text is interpolated directly into the status dashboard).
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/zubair-trabzada/ai-legal-claude/main/install.sh, https://raw.githubusercontent.com/zubair-trabzada/ai-marketing-claude/main/install.sh, https://raw.githubusercontent.com/zubair-trabzada/ai-sales-claude/main/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 07:10 AM
Security Audit — agent-trust-hub — agency-stack