chinese-legal-builder-hub

Fail

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill includes functionality for skill-installer and auto-updater, which are designed to download and deploy executable code from community repositories into the user's environment. This presents a high risk of executing unverified or malicious logic.
  • [EXTERNAL_DOWNLOADS]: The skill is configured to fetch content from the claude-for-legal-ZH/legal-builder-hub repository and other unspecified 'community' sources. These sources are not recognized as trusted vendors and may host malicious skill definitions.
  • [DATA_EXFILTRATION]: The instructions direct the agent to read sensitive configuration profiles located in ~/.claude/plugins/config/ and ~/.codex/legal-zh/. These paths are outside the standard project scope and typically contain environment settings or credentials that should not be accessed by untrusted skills.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary purpose is to ingest and process 'community skills.' This creates a significant attack surface where malicious instructions embedded in community-contributed files could be executed by the agent or used to override safety protocols.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 17, 2026, 07:43 AM
Security Audit — agent-trust-hub — chinese-legal-builder-hub