valet
Fail
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and installs the Homebrew package manager using the official installation script from
https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh. It also installs thevalet-clifrom the author's official tap viabrew install valetdotdev/tap/valet-cli.- [REMOTE_CODE_EXECUTION]: The skill executes the Homebrew installer script directly via a shell command substitution:bash -c "$(curl ...)". This is the standard method for installing this well-known service.- [COMMAND_EXECUTION]: The skill makes extensive use of thevaletCLI and other tools such asbrewandnpxto manage agent projects, authentication, and deployment.- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads session logs from~/.claude/projects/to facilitate its 'learning' functionality, which captures user workflows to generate new agents. The skill explicitly instructs the agent to never ask for secret values within the LLM session, directing users to local terminal commands instead.- [INDIRECT_PROMPT_INJECTION]: The skill has a defined surface for processing untrusted data which could contain malicious instructions. - Ingestion points: It reads session logs (
.jsonlfiles), fetches content from external URLs (GitHub, npmjs, skills.sh), and processes incoming webhook payloads. - Boundary markers: For webhooks, it uses specific instructions to delimit the payload (e.g., 'The JSON webhook payload is appended directly after these instructions').
- Capability inventory: The skill has access to the
bashtool for command execution and file system write operations. - Sanitization: The skill includes logic to replace specific identifiers with placeholders when generating agent files from session data.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh - DO NOT USE without thorough review
Audit Metadata