skills/aeondave/malskill/mimipenguin/Gen Agent Trust Hub

mimipenguin

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Downloads scripts from an untrusted third-party GitHub repository (https://github.com/huntergregal/mimipenguin).
  • [REMOTE_CODE_EXECUTION]: Encourages the execution of code fetched from a remote repository (mimipenguin.py, mimipenguin.sh) without verification.
  • [COMMAND_EXECUTION]: Executes commands to read sensitive process memory files (/proc/PID/mem) to extract credentials from GNOME Keyring, SSH agent, and other services.
  • [PRIVILEGE_ESCALATION]: Explicitly requires and uses sudo to run external scripts, granting the untrusted code full administrative access to the host system.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:56 AM
Security Audit — agent-trust-hub — mimipenguin