perl-cpan-ecosystem

Fail

Audited by Gen Agent Trust Hub on Mar 3, 2026

Risk Level: HIGHCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The guide provides instructions to use sudo for installing system packages and build dependencies via apt and other package managers.
  • [REMOTE_CODE_EXECUTION]: The documentation includes the standard method for installing cpanm by downloading a script from https://cpanmin.us and piping it directly to the perl interpreter.
  • [COMMAND_EXECUTION]: The skill includes steps to modify shell configuration files such as ~/.bashrc or ~/.zshrc to persistently initialize the local::lib environment variables.
Recommendations
  • HIGH: Downloads and executes remote code from: https://cpanmin.us - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 3, 2026, 02:03 PM