skills/gvieira18/skills/waifu-it/Gen Agent Trust Hub

waifu-it

Warn

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill facilitates the transmission of local files to an external third-party domain (https://waifuvault.moe/rest).
  • The bundled script scripts/waifu-it uses curl to perform multipart uploads of files provided via absolute paths.
  • This capability creates an attack surface for the exfiltration of sensitive data, such as environment variables (.env), SSH keys, or cloud credentials, if the agent is manipulated into processing these paths.
  • [COMMAND_EXECUTION]: The skill relies on the execution of a bundled bash script to perform its operations.
  • Instructions in SKILL.md direct the agent to execute the bundled script scripts/waifu-it using bash and passing absolute file paths as arguments.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 20, 2026, 03:50 AM
Security Audit — agent-trust-hub — waifu-it