China-CF-Study

Fail

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands such as npx and uvx to install external Model Context Protocol (MCP) servers.
  • [REMOTE_CODE_EXECUTION]: The installation process for MCP servers, as directed in the asset/MCP.docx file, involves downloading and executing remote code from external sources.
  • [COMMAND_EXECUTION]: The skill provides instructions to modify sensitive agent configuration files, specifically ~/.claude.json and settings.json, to integrate external tools into the core execution environment.
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to retrieve data and tools from various external sources, including commercial databases and government websites, relying on instructions provided in non-vetted secondary files.
  • [DATA_EXFILTRATION]: By modifying core configuration files and facilitating external code execution via MCP servers, the skill establishes a potential vector for data exfiltration or credential harvesting if the third-party components are malicious.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 22, 2026, 03:11 AM
Security Audit — agent-trust-hub — China-CF-Study