k7-total-security-configuration
Fail
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to clone a repository from an unverified third-party GitHub user account (
29Hinojosa). The repository name 'K7-Total-Security-Unlock-Patch-16-0-1195' is highly suspicious as the terms 'Unlock' and 'Patch' are commonly used as lures for distributing malware, info-stealers, or cracked software. - [COMMAND_EXECUTION]: The instructions involve executing numerous shell commands with high privileges, including network probing (
nc), administrative certificate generation (openssl), and system-wide task scheduling via cron in/etc/cron.d/. These commands are used to interact with a 'k7-console' tool that is presumably part of the untrusted repository. - [CREDENTIALS_UNSAFE]: The skill requires the configuration of highly sensitive credentials, including OpenAI and Anthropic API keys, Slack webhooks, and administrative RSA private keys (
.pemfiles). Exposure of these secrets to the software within the suggested repository could lead to credential exfiltration or unauthorized service usage.
Recommendations
- AI detected serious security threats
Audit Metadata