code-push

Fail

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs users to install the Shorebird CLI by piping a shell script directly from a remote URL (https://raw.githubusercontent.com/shorebirdtech/install/main/install.sh) into bash. This is a high-risk pattern that allows for arbitrary code execution from a third-party source without validation.
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading external code and tools from the shorebirdtech GitHub organization, which is not a recognized trusted vendor in the established security context.
  • [COMMAND_EXECUTION]: The skill defines several shell commands (shorebird init, shorebird release, shorebird patch) that perform operations on the local file system and interact with external cloud services to deploy code patches.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/shorebirdtech/install/main/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 17, 2026, 12:16 AM