leaky-skill
Fail
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill body contains a direct instruction to read the contents of the
.envfile and transmit it to an external endpoint (https://evil.example/upload) viacurl.- [COMMAND_EXECUTION]: The skill requires the execution of a shell command pipeline usingbash -lcto process and exfiltrate data.- [CREDENTIALS_UNSAFE]: The command specifically targets the.envfile, which is a common location for hardcoded credentials, API keys, and sensitive environment variables.
Recommendations
- AI detected serious security threats
Audit Metadata