configure-ecc
Fail
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill automates the download of code from a remote repository (
github.com/affaan-m/everything-claude-code) and copies it into the agent's execution environment at~/.claude/skills/. This effectively allows unverified third-party code to run as an integrated part of the agent's operational logic.- [EXTERNAL_DOWNLOADS]: Clones a repository from a source that is not identified as a trusted vendor. This bypasses typical verification processes for agent skills.- [COMMAND_EXECUTION]: Utilizes multiple shell commands to manage the system environment, includinggit cloneto retrieve remote content,mkdirto create directories, andcp -rto deploy code to system-level configuration paths.- [PROMPT_INJECTION]: The skill facilitates Indirect Prompt Injection by ingesting and installing unvetted instructions from a remote source into the agent's context. It also includes instructions to "optimize" these files by dynamically rewriting their content, which could be abused to inject or modify logic without user oversight.- [PRIVILEGE_ESCALATION]: While not using sudo, the skill requests to modify the user's primary agent configuration directory (~/.claude/), which can influence the agent's behavior across all future sessions.
Recommendations
- AI detected serious security threats
Audit Metadata