external-gitcode-ascend-security-code-review

Fail

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: CRITICAL
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The file references/markdown.md includes a reference to http://malicious-site.com/tool.exe. This is explicitly labeled as a negative example of a suspicious link in a security auditing guide and is not an actual attempt to download or execute malicious software.\n- [REMOTE_CODE_EXECUTION]: Snippets in references/python.md demonstrate the insecure use of eval() and exec(). These are presented as non-compliant examples for security review training and are not executed by the agent.\n- [COMMAND_EXECUTION]: references/shell.md provides examples of destructive commands such as rm -rf / resulting from unquoted variables. These are used to illustrate common shell script vulnerabilities and do not represent a threat from the skill logic.\n- [SAFE]: The skill is a comprehensive auditing resource from ascend-ai-coding. Its primary function is to provide a reference for security best practices. The patterns detected by automated scanners are integral parts of its educational corpus.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
May 19, 2026, 06:28 AM
Security Audit — agent-trust-hub — external-gitcode-ascend-security-code-review