k7-total-security-configuration

Fail

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to clone a repository from an unverified third-party GitHub user account (29Hinojosa). The repository name 'K7-Total-Security-Unlock-Patch-16-0-1195' is highly suspicious as the terms 'Unlock' and 'Patch' are commonly used as lures for distributing malware, info-stealers, or cracked software.
  • [COMMAND_EXECUTION]: The instructions involve executing numerous shell commands with high privileges, including network probing (nc), administrative certificate generation (openssl), and system-wide task scheduling via cron in /etc/cron.d/. These commands are used to interact with a 'k7-console' tool that is presumably part of the untrusted repository.
  • [CREDENTIALS_UNSAFE]: The skill requires the configuration of highly sensitive credentials, including OpenAI and Anthropic API keys, Slack webhooks, and administrative RSA private keys (.pem files). Exposure of these secrets to the software within the suggested repository could lead to credential exfiltration or unauthorized service usage.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 8, 2026, 04:50 AM
Security Audit — agent-trust-hub — k7-total-security-configuration