Back to skill

Security audit

CLI-Hub Skill for CLI-Anything

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed CLI marketplace helper, but it directs agents to install unpinned packages from a mutable live catalog without clear review or approval safeguards.

Review this skill before installing. Use it only when you explicitly want CLI-Hub package discovery or installation, and install packages in a disposable or least-privileged environment after checking the package name, version, source, and maintainer trust. Do not run catalog-suggested install commands automatically in a workspace with sensitive files or credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:13
Finding

Unpinned Third-Party Package Installation Through a Mutable External Catalog

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13–26, 32–38, 58–64, and 69–81
Vulnerability Type: Supply-chain exposure caused by unpinned dependencies and a mutable external package catalog
Risk Level: High

Vulnerable Code

markdown
## Quick Start

```bash
# Install the CLI Hub package manager
pip install cli-anything-hub

# Browse all available CLIs
cli-hub list

# Search by category or keyword
cli-hub search image
cli-hub search "3d modeling"

# Install a CLI
cli-hub install gimp
text

```markdown
## Live Catalog

**URL**: [`https://clianything.cc/SKILL.txt`](https://clianything.cc/SKILL.txt)

The catalog is auto-updated and provides:
- Full list of available CLIs organized by category
- One-line `cli-hub install` commands for each tool
markdown
`cli-hub` is a lightweight wrapper around `pip`. When you run `cli-hub install gimp`, it installs a separate Python package (`cli-anything-gimp`) with its own CLI entry point (`cli-anything-gimp`). Each CLI is an independent pip package — `cli-hub` simply resolves names from the registry and tracks installs.

## How to Use

1. **Install cli-hub**: `pip install cli-anything-hub`
2. **Find your tool**: `cli-hub search <keyword>` or `cli-hub list -c <category>`
3. **Install**: `cli-hub install <name>` (installs the `cli-anything-<name>` pip package)
markdown
## Example Workflow

```bash
# Install the hub
pip install cli-anything-hub

# Find what you need
cli-hub search video

# Install it
cli-hub install kdenlive

# Use it with JSON output
cli-anything-kdenlive --json project create --name my-project
text

### Technical Analysis

The Skill instructs an agent to install `cli-anything-hub` directly from the package index without specifying an audited version or cryptographic hash. It then delegates the selection and installation of additional independent 
...[truncated 2534 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin cli-anything-hub and every approved downstream package to an explicitly reviewed version.
  2. Require cryptographic hashes for downloaded artifacts, such as through a locked requirements file and pip's --require-hashes option.
  3. Replace mutable catalog resolution with a versioned, signed, and reviewable manifest.
  4. Maintain an allowlist mapping approved CLI names to exact package names, versions, artifact hashes, and trusted sources.
  5. Verify package provenance and signatures where supported, and retain software-bill-of-materials and audit metadata.
  6. Review package source code, build configuration, dependencies, and entry points before adding a package to the allowlist.
  7. Prefer an internally controlled package mirror containing only reviewed artifacts rather than resolving arbitrary current releases from a public index.
  8. Install and execute packages in an isolated environment or disposable sandbox with minimal filesystem access, no unnecessary credentials, restricted network access, and no administrative privileges.
  9. Separate package discovery from installation and require explicit approval before executing an installation command recommended by the remote catalog.
  10. Document safe upgrade procedures so new package versions are reviewed and their hashes updated before deployment.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description is very broad and does not define clear trigger boundaries, which can cause an agent to invoke this skill in many unrelated contexts. Because the skill encourages package discovery and installation, over-broad activation increases the chance that an agent will fetch or install unreviewed third-party software when a safer or more specific capability should have been used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown instructs the agent to install packages from a live remote catalog without warning that the catalog contents can change and may reference untrusted third-party packages. This creates a supply-chain risk: an agent following these instructions could automatically install attacker-controlled or compromised packages via pip, leading to arbitrary code execution or environment compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.