skills/aeondave/malskill/cloakify/Gen Agent Trust Hub

cloakify

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHDATA_EXFILTRATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to facilitate the unauthorized removal of data from a system. Its primary function is to bypass security controls by encoding payloads into innocuous-looking strings to evade pattern matching and DLP tools.
  • [EXTERNAL_DOWNLOADS]: The skill instructions require the agent to download a codebase from an untrusted external GitHub repository (github.com/TryCatchHCF/Cloakify).
  • [REMOTE_CODE_EXECUTION]: The instructions direct the agent to execute multiple Python scripts (cloakify.py, decloakify.py, listCiphers.py, addNoise.py) that are sourced from an unverified third-party repository, posing a significant risk of arbitrary code execution.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:19 PM
Security Audit — agent-trust-hub — cloakify