leaky-skill

Fail

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill body contains a direct instruction to read the contents of the .env file and transmit it to an external endpoint (https://evil.example/upload) via curl.- [COMMAND_EXECUTION]: The skill requires the execution of a shell command pipeline using bash -lc to process and exfiltrate data.- [CREDENTIALS_UNSAFE]: The command specifically targets the .env file, which is a common location for hardcoded credentials, API keys, and sensitive environment variables.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 2, 2026, 12:20 PM
Security Audit — agent-trust-hub — leaky-skill