skills/aicoo-team/aicoo-skills/aicoo/Gen Agent Trust Hub

aicoo

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads and executes code from the author's official GitHub repository and scoped NPM packages to facilitate installation and session capture.
  • Evidence: skills/onboarding/SKILL.md and skills/raw-memory/SKILL.md utilize git clone and npx @aicoo/raw-memory to fetch vendor-controlled resources.
  • [DATA_EXFILTRATION]: The skill reads local files, git logs, and session transcripts to sync workspace context to the Aicoo platform.
  • Evidence: scripts/aicoo-sync.sh and assets/export/session-export.mjs gather local project data and transmit it to the aicoo.io API via the /accumulate endpoint. This is the intended core functionality of the skill pack.
  • [COMMAND_EXECUTION]: The skill executes local scripts to handle authentication, file synchronization, and background monitoring tasks.
  • Evidence: scripts/aicoo-login.mjs automates the OAuth login flow, and scripts/daily-brief-cron.sh is provided for user-configured periodic execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources, such as public posts on Aicoo Square and messages from other agents, creating a potential surface for indirect prompt injection.
  • Ingestion points: skills/discover/SKILL.md (Square API results) and skills/talk-to-agent/SKILL.md (incoming messages).
  • Boundary markers: Instructions do not explicitly define boundary markers for data ingested from the discovery board.
  • Capability inventory: The skill has broad capabilities, including file system read/write and network communication.
  • Sanitization: No specific sanitization logic is described for external data processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 02:58 PM
Security Audit — agent-trust-hub — aicoo