unconstrained-file-reader

Fail

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The read_caller_path function in read.py utilizes open(path) with an unvalidated, caller-supplied string. This capability allows the skill to access sensitive file paths such as .ssh/id_rsa, .env, and system configuration files that may contain secrets.
  • [DATA_EXFILTRATION]: The skill provides an unconstrained file reading capability. As described in SKILL.md, it is explicitly designed to read paths 'without confining it to a safe root', which creates a significant data exposure risk where internal or private files can be read into the agent's context.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 9, 2026, 11:40 AM
Security Audit — agent-trust-hub — unconstrained-file-reader