chinese-legal-builder-hub
Fail
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill includes functionality for
skill-installerandauto-updater, which are designed to download and deploy executable code from community repositories into the user's environment. This presents a high risk of executing unverified or malicious logic. - [EXTERNAL_DOWNLOADS]: The skill is configured to fetch content from the
claude-for-legal-ZH/legal-builder-hubrepository and other unspecified 'community' sources. These sources are not recognized as trusted vendors and may host malicious skill definitions. - [DATA_EXFILTRATION]: The instructions direct the agent to read sensitive configuration profiles located in
~/.claude/plugins/config/and~/.codex/legal-zh/. These paths are outside the standard project scope and typically contain environment settings or credentials that should not be accessed by untrusted skills. - [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and process 'community skills.' This creates a significant attack surface where malicious instructions embedded in community-contributed files could be executed by the agent or used to override safety protocols.
Recommendations
- AI detected serious security threats
Audit Metadata