skills/erphq/skills/manage-env/Gen Agent Trust Hub

manage-env

Fail

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: HIGHDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill requires access to sensitive credential files located at ~/.build-host/credentials.json to authenticate with an external service. Accessing authentication tokens stored on the filesystem is a high-risk operation that could result in credential harvesting.
  • [PROMPT_INJECTION]: The skill's metadata identifies the author as 'build.host', which directly contradicts the actual author 'erphq'. This misleading information constitutes metadata poisoning and can lead users or agents to erroneously trust the skill's origin and capabilities.
  • [PROMPT_INJECTION]: The skill processes untrusted data from user project directories and git repositories to drive deployment operations without implementing boundary markers or sanitization. This creates a surface for indirect prompt injection. 1. Ingestion points: User-provided project directories and repository contents. 2. Boundary markers: None identified. 3. Capability inventory: Filesystem read access and network interaction via the build.host API (GET/POST). 4. Sanitization: No data sanitization or validation steps are described for ingested project content.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 6, 2026, 04:44 PM
Security Audit — agent-trust-hub — manage-env