podkop-openwrt-guide

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions to download and execute an installation shell script from the vendor's GitHub repository (itdoginfo/podkop). This is a remote code execution pattern common for router utilities; however, the skill explicitly warns users to pin specific versions and manually inspect the script content before execution.
  • [COMMAND_EXECUTION]: The orchestration tool utilizes extensive shell scripts to perform administrative tasks on the host router, including modifications to nftables, dnsmasq, and system service lifecycle management. These high-privilege operations are core to the skill's purpose of managing network routing and proxy services.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest remote domain and subnet lists from external URLs. This creates a surface for indirect prompt injection where malicious data in external sources could influence agent logic. The skill mitigates this by documenting external data as untrusted and including validation logic for IPv4, CIDR, and domain patterns in its shell libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 04:03 PM