slow-lane
Fail
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill discloses exact file paths to sensitive configuration and key files, and instructs on how to retrieve the associated tokens.
- Evidence: Identifies
/home/aaron/repos/arc-llm-proxy/deploy/.keys.env,deploy/veles.key, anddeploy/keys.local.jsonas locations for authentication keys. - Evidence: Explicitly instructs to
sourcethe.keys.envfile to obtain theFACTORY_KEY. - [DATA_EXFILTRATION]: The instructions expose internal network infrastructure details.
- Evidence: Discloses internal LAN IP addresses
192.168.1.159and192.168.1.103used for model hosting and proxy services. - [COMMAND_EXECUTION]: The skill provides several shell commands for interacting with the environment and managing services.
- Evidence: Includes a
curlusage example that interpolates sourced credentials and targets local infrastructure. - Evidence: Provides administrative commands to identify processes using
ssand relaunch the proxy server using Node.js with complex environment variables. - [EXTERNAL_DOWNLOADS]: The skill references a connection to an external cloud GPU tunnel.
- Evidence: Mentions the use of a
trycloudflare.comtunnel for theeVelesendpoint.
Recommendations
- AI detected serious security threats
Audit Metadata