RobotX Deploy CLI
PassAudited by VirusTotal on May 11, 2026.
Findings (1)
The skill instructions in SKILL.md direct the agent to install software using 'curl | bash' from a remote GitHub repository (haibingtown/robotx_cli), which is a high-risk pattern that could lead to arbitrary code execution. While the tool's stated purpose is application deployment, the instructions encourage the agent to execute unverified remote scripts and manage sensitive credentials (ROBOTX_API_KEY), posing a significant security risk if the remote source is compromised.
