skills-broadcast
Fail
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The
run.shscript performs wide-ranging filesystem modifications, including recursive deletion and symbolic link creation across multiple IDE configuration directories (e.g.,~/.claude,~/.codex,~/.pi,~/.kilocode). - [COMMAND_EXECUTION]: The
cleanupfeature inrun.shexplicitly executessudo rm -rfto delete directories it identifies as backups. This provides the skill with root-level deletion authority, which is a high-risk capability that could lead to system instability or data loss if misused. - [DATA_EXFILTRATION]: The
git-syncfunction inrun.shautomates the transmission of local skill directories to an external GitHub repository (github.com/grahama1970/agent-skills). This facilitates the export of potentially private local data to a public or remote platform. - [CREDENTIALS_UNSAFE]: The script attempts to prune
.envfiles before pushing to GitHub; however, this manual exclusion list is not exhaustive and does not guarantee that other sensitive data, hardcoded API keys, or private configuration files will not be exposed during the remote synchronization process.
Recommendations
- AI detected serious security threats
Audit Metadata