configure-ecc

Fail

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill automates the download of code from a remote repository (github.com/affaan-m/everything-claude-code) and copies it into the agent's execution environment at ~/.claude/skills/. This effectively allows unverified third-party code to run as an integrated part of the agent's operational logic.- [EXTERNAL_DOWNLOADS]: Clones a repository from a source that is not identified as a trusted vendor. This bypasses typical verification processes for agent skills.- [COMMAND_EXECUTION]: Utilizes multiple shell commands to manage the system environment, including git clone to retrieve remote content, mkdir to create directories, and cp -r to deploy code to system-level configuration paths.- [PROMPT_INJECTION]: The skill facilitates Indirect Prompt Injection by ingesting and installing unvetted instructions from a remote source into the agent's context. It also includes instructions to "optimize" these files by dynamically rewriting their content, which could be abused to inject or modify logic without user oversight.- [PRIVILEGE_ESCALATION]: While not using sudo, the skill requests to modify the user's primary agent configuration directory (~/.claude/), which can influence the agent's behavior across all future sessions.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 1, 2026, 11:08 AM
Security Audit — agent-trust-hub — configure-ecc