China-CF-Study
Fail
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands such as npx and uvx to install external Model Context Protocol (MCP) servers.
- [REMOTE_CODE_EXECUTION]: The installation process for MCP servers, as directed in the asset/MCP.docx file, involves downloading and executing remote code from external sources.
- [COMMAND_EXECUTION]: The skill provides instructions to modify sensitive agent configuration files, specifically ~/.claude.json and settings.json, to integrate external tools into the core execution environment.
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to retrieve data and tools from various external sources, including commercial databases and government websites, relying on instructions provided in non-vetted secondary files.
- [DATA_EXFILTRATION]: By modifying core configuration files and facilitating external code execution via MCP servers, the skill establishes a potential vector for data exfiltration or credential harvesting if the third-party components are malicious.
Recommendations
- AI detected serious security threats
Audit Metadata