skills/aeondave/malskill/liffy/Gen Agent Trust Hub

liffy

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions involve cloning an external repository (https://github.com/mzfr/liffy) and executing its content using python3 liffy.py. This allows the execution of arbitrary code from an unverified third-party source inside the agent's execution environment.
  • [EXTERNAL_DOWNLOADS]: The skill fetches tools at runtime from a GitHub repository not associated with a trusted organization, creating a supply chain risk.
  • [CREDENTIALS_UNSAFE]: The skill explicitly references paths to sensitive data including /home//.ssh/id_rsa (SSH keys), /proc/self/environ (potential API keys/secrets), and /var/lib/php/sessions/ (session tokens).
  • [COMMAND_EXECUTION]: The skill relies on shell command execution (git clone, python3) for downloading and running exploitation scripts.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 5, 2026, 10:41 PM
Security Audit — agent-trust-hub — liffy