here-now
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: CRITICAL
Full Analysis
- [SAFE]: The skill implements secure API key management by instructing agents to store credentials in a local file (
~/.herenow/credentials) using restrictive permissions (chmod 600). This follows standard security practices for managing sensitive tokens and prevents unintended access by other local users. - [SAFE]: File upload and network operations are restricted to the vendor's official domain (
here.now) and trusted infrastructure providers (Cloudflare R2 atcloudflarestorage.com). These activities are fully documented and necessary for the skill's primary function of hosting and managing user content. - [SAFE]: Automated malware alerts for the helper scripts (
publish.shanddrive.sh) were evaluated and determined to be false positives. The scripts contain transparent, standard Bash logic for API communication and do not perform any hidden, obfuscated, or malicious actions. The flags likely originated from the scripts' core capabilities of handling authentication tokens and performing network uploads. - [COMMAND_EXECUTION]: The helper scripts utilize established system binaries (
curl,jq,file) for processing metadata and interacting with the here.now API. The command usage is strictly scoped to the skill's documented workflows and does not incorporate arbitrary user-supplied command execution.
Recommendations
- CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata