enter-services

Fail

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill instructs the agent to modify the user's ~/.ssh/config file and references specific identity files such as ~/.ssh/enter-services-shared-key and ~/.ssh/enter-services-staging-key.
  • [CREDENTIALS_UNSAFE]: Sensitive environment variables are decrypted using sops and temporarily stored in the /tmp/ directory, which is a shared location that may pose risks in multi-user environments.
  • [COMMAND_EXECUTION]: The skill makes extensive use of sudo to manage system services (systemctl), inspect system logs (journalctl), and install system-level packages via apt-get.
  • [EXTERNAL_DOWNLOADS]: The skill clones the project repository from an external GitHub URL and installs dependencies using npm and homebrew.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 6, 2026, 04:52 PM
Security Audit — agent-trust-hub — enter-services