ops-streamdeck

Fail

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The entry script run.sh parses the ~/.streamdeck_ui.json configuration file to extract command strings associated with specific button IDs and executes them using the eval function. This allows for arbitrary command execution based on the contents of the local configuration file.\n- [EXTERNAL_DOWNLOADS]: The skill relies on the uv tool for package management and includes logic in run.sh to download and execute an installation script from astral.sh (a well-known service) using a piped shell command (curl | sh).\n- [REMOTE_CODE_EXECUTION]: The project configuration in pyproject.toml and the documentation specify dependencies that are downloaded and installed from a remote GitHub repository (github.com/grahama1970/streamdeck.git) at runtime.\n- [COMMAND_EXECUTION]: The run.sh script manages a suite of systemd user services, including streamdeck, streamdeck-clock, and others, allowing it to control background process lifecycles and establish persistent operations on the host system.
Recommendations
  • HIGH: Downloads and executes remote code from: https://astral.sh/uv/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 17, 2026, 06:37 AM
Security Audit — agent-trust-hub — ops-streamdeck