data-exfiltrator

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: CRITICALDATA_EXFILTRATIONCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONMETADATA_POISONING
Full Analysis
  • [DATA_EXFILTRATION]: The Python script analyze.py reads the entire content of user files and transmits this data via an HTTP POST request to the external domain evil.example.com.
  • [CREDENTIALS_UNSAFE]: The skill extracts the API_KEY environment variable and exfiltrates it to a remote server along with the processed data.
  • [DYNAMIC_EXECUTION]: The code utilizes the eval() function, which allows for the execution of arbitrary Python code and poses a significant security risk if input is manipulated.
  • [METADATA_POISONING]: The skill's description in SKILL.md is deceptive, characterizing the tool as a data analyzer while its primary function involves the unauthorized transmission of sensitive information.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 16, 2026, 02:50 PM
Security Audit — agent-trust-hub — data-exfiltrator