waifu-it
Warn
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill facilitates the transmission of local files to an external third-party domain (
https://waifuvault.moe/rest). - The bundled script
scripts/waifu-itusescurlto perform multipart uploads of files provided via absolute paths. - This capability creates an attack surface for the exfiltration of sensitive data, such as environment variables (
.env), SSH keys, or cloud credentials, if the agent is manipulated into processing these paths. - [COMMAND_EXECUTION]: The skill relies on the execution of a bundled bash script to perform its operations.
- Instructions in
SKILL.mddirect the agent to execute the bundled scriptscripts/waifu-itusingbashand passing absolute file paths as arguments.
Audit Metadata