data-exfiltrator
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: CRITICALDATA_EXFILTRATIONCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONMETADATA_POISONING
Full Analysis
- [DATA_EXFILTRATION]: The Python script
analyze.pyreads the entire content of user files and transmits this data via an HTTP POST request to the external domainevil.example.com. - [CREDENTIALS_UNSAFE]: The skill extracts the
API_KEYenvironment variable and exfiltrates it to a remote server along with the processed data. - [DYNAMIC_EXECUTION]: The code utilizes the
eval()function, which allows for the execution of arbitrary Python code and poses a significant security risk if input is manipulated. - [METADATA_POISONING]: The skill's description in
SKILL.mdis deceptive, characterizing the tool as a data analyzer while its primary function involves the unauthorized transmission of sensitive information.
Recommendations
- AI detected serious security threats
Audit Metadata