arkts-skill

Warn

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes maintenance and search scripts (scripts/fetch_huawei_migration_refs.sh, scripts/search_chapters.sh, scripts/rebuild_chapters.py) that execute shell commands. The search script passes user-controlled strings to the rg utility, and the fetch script relies on an external dependency located in the user's home directory ($HOME/.claude/skills/fetch-skill/...).- [REMOTE_CODE_EXECUTION]: The documentation refresh script (scripts/fetch_huawei_migration_api.py) fetches remote HTML content from an external API and processes it through a subprocess call to the pandoc system utility. This pattern of network fetch followed by system utility execution with the downloaded data constitutes a medium-risk execution vector.- [EXTERNAL_DOWNLOADS]: The skill fetches documentation and API data from Huawei's developer portal domains (svc-drcn.developer.huawei.com, developer.huawei.com). these are recognized as established service domains.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 01:53 PM
Security Audit — agent-trust-hub — arkts-skill