od-contribute

Fail

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill's documentation and installation script encourage a highly risky execution pattern where a remote script is fetched via curl and piped directly into bash. This pattern is observed in SKILL.md and install.sh targeting the nexu-io/open-design repository.
  • [EXTERNAL_DOWNLOADS]: During installation, the install.sh script downloads a repository tarball from github.com/nexu-io/open-design and extracts it into the local filesystem.
  • [COMMAND_EXECUTION]: The skill operates by executing a suite of internal shell scripts (e.g., setup-workspace.sh, create-pr.sh, create-issue.sh) that use the gh (GitHub) and git CLI tools to modify the local filesystem and interact with remote repositories. These scripts process user-provided strings such as 'slugs' and 'paths'.
  • [CREDENTIALS_UNSAFE]: The skill provides instructions and logic to harvest GitHub authentication tokens using gh auth token and store them in a plaintext file named .gh-token inside the skill's own directory. While intended to resolve sandbox restrictions for tools like Codex or Cursor, this practice exposes sensitive credentials to the AI agent and any process with access to the skill folder.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/nexu-io/open-design/main/.claude/skills/od-contribute/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — od-contribute