aicoo
Pass
Audited by Gen Agent Trust Hub on Aug 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads and executes code from the author's official GitHub repository and scoped NPM packages to facilitate installation and session capture.
- Evidence:
skills/onboarding/SKILL.mdandskills/raw-memory/SKILL.mdutilizegit cloneandnpx @aicoo/raw-memoryto fetch vendor-controlled resources. - [DATA_EXFILTRATION]: The skill reads local files, git logs, and session transcripts to sync workspace context to the Aicoo platform.
- Evidence:
scripts/aicoo-sync.shandassets/export/session-export.mjsgather local project data and transmit it to theaicoo.ioAPI via the/accumulateendpoint. This is the intended core functionality of the skill pack. - [COMMAND_EXECUTION]: The skill executes local scripts to handle authentication, file synchronization, and background monitoring tasks.
- Evidence:
scripts/aicoo-login.mjsautomates the OAuth login flow, andscripts/daily-brief-cron.shis provided for user-configured periodic execution. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources, such as public posts on Aicoo Square and messages from other agents, creating a potential surface for indirect prompt injection.
- Ingestion points:
skills/discover/SKILL.md(Square API results) andskills/talk-to-agent/SKILL.md(incoming messages). - Boundary markers: Instructions do not explicitly define boundary markers for data ingested from the discovery board.
- Capability inventory: The skill has broad capabilities, including file system read/write and network communication.
- Sanitization: No specific sanitization logic is described for external data processed by the agent.
Audit Metadata