ops-streamdeck
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The entry script
run.shparses the~/.streamdeck_ui.jsonconfiguration file to extract command strings associated with specific button IDs and executes them using theevalfunction. This allows for arbitrary command execution based on the contents of the local configuration file.\n- [EXTERNAL_DOWNLOADS]: The skill relies on theuvtool for package management and includes logic inrun.shto download and execute an installation script fromastral.sh(a well-known service) using a piped shell command (curl | sh).\n- [REMOTE_CODE_EXECUTION]: The project configuration inpyproject.tomland the documentation specify dependencies that are downloaded and installed from a remote GitHub repository (github.com/grahama1970/streamdeck.git) at runtime.\n- [COMMAND_EXECUTION]: Therun.shscript manages a suite of systemd user services, includingstreamdeck,streamdeck-clock, and others, allowing it to control background process lifecycles and establish persistent operations on the host system.
Recommendations
- HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata