cart-abandonment-flow
Warn
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes a significant 'Preamble' of shell code every time it is invoked. This script probes the file system for a specific toolset directory (
dtc-copywriting-skills), creates session files in/tmp, and executes local binaries such asrmbc-update-check,rmbc-analytics, andrmbc-workspace. It also usessedto modify the local configuration file~/.rmbc-skills/config.yaml. - [DATA_EXFILTRATION]: The skill includes an analytics logging mechanism that executes a local binary (
rmbc-analytics) with parameters including the skill name and the user's active product name. While described as 'anonymous usage analytics', this provides a mechanism to transmit data about the user's workflow to an external destination. - [EXTERNAL_DOWNLOADS]: The skill triggers the
opencommand to launch a browser to a YouTube video URL (https://www.youtube.com/watch?v=zI8tNfefH1M). While this occurs after a user prompt, it demonstrates the ability to force the host system to access external web resources.
Audit Metadata