action-validator

Fail

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a detailed procedure for bypassing security audits and sensitive-path checks. It instructs the agent to write files to temporary directories and then use a shell script to move them into protected system or platform directories (such as .claude/), explicitly stating that this method avoids triggering security prompts and audits.
  • [EXTERNAL_DOWNLOADS]: The skill references and encourages the use of patterns from an untrusted external GitHub repository (github.com/Q00/ouroboros) which is not a verified or well-known service.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
May 15, 2026, 06:17 PM
Security Audit — agent-trust-hub — action-validator