agency-stack
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using
bashto verify the presence of tool suites. Specifically, it usestest -fto check forSKILL.mdfiles andfindpiped towc -lto count sub-skills in local directories (~/.claude/skills/). This behavior is consistent with its stated purpose of status checking. - [REMOTE_CODE_EXECUTION]: The skill contains multiple pre-formatted shell commands that download scripts and pipe them directly into bash (e.g.,
curl -sL https://raw.githubusercontent.com/zubair-trabzada/ai-marketing-claude/main/install.sh | bash). Although the instructions specify displaying these commands to the user rather than the agent executing them automatically, the use of thecurl | bashpattern from external sources is a high-risk installation method. Note: The resources are hosted by the skill's author (zubair-trabzada). - [INDIRECT_PROMPT_INJECTION]: The skill parses data from local files, including
VERSIONfiles and metadata fromSKILL.md, to generate its status report. This creates an attack surface where a compromised or malicious tool suite could influence the agent's behavior by embedding instructions in these files. - Ingestion points: Reads
VERSION,SKILL.md,package.json, andmetadata.jsonfrom suite directories. - Boundary markers: None (the skill simply displays the extracted information).
- Capability inventory: File system discovery via
findand command execution viabashfor status checking. - Sanitization: None (extracted text is interpolated directly into the status dashboard).
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/zubair-trabzada/ai-legal-claude/main/install.sh, https://raw.githubusercontent.com/zubair-trabzada/ai-marketing-claude/main/install.sh, https://raw.githubusercontent.com/zubair-trabzada/ai-sales-claude/main/install.sh - DO NOT USE without thorough review
Audit Metadata