Why Ethereum
Warn
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
catalog.jsonfile contains aninstall.commandfield that executescurl -s https://ethskills.com/why/SKILL.md, representing an automated or suggested shell command execution to fetch remote content. - [EXTERNAL_DOWNLOADS]: The
setupblock incatalog.jsonsuggests installing external software viaclaude plugin install https://github.com/austintgriffith/ethskillsandclawhub install ethskills. These operations involve downloading and executing code from external, non-verified third-party repositories. - [DATA_EXFILTRATION]: The skill performs network operations to the domain
ethskills.comwhich is not on the standard whitelist of trusted services.
Audit Metadata