unconstrained-file-reader
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATION
Full Analysis
- [CREDENTIALS_UNSAFE]: The
read_caller_pathfunction inread.pyutilizesopen(path)with an unvalidated, caller-supplied string. This capability allows the skill to access sensitive file paths such as.ssh/id_rsa,.env, and system configuration files that may contain secrets. - [DATA_EXFILTRATION]: The skill provides an unconstrained file reading capability. As described in
SKILL.md, it is explicitly designed to read paths 'without confining it to a safe root', which creates a significant data exposure risk where internal or private files can be read into the agent's context.
Recommendations
- AI detected serious security threats
Audit Metadata