od-contribute
Fail
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill's documentation and installation script encourage a highly risky execution pattern where a remote script is fetched via
curland piped directly intobash. This pattern is observed inSKILL.mdandinstall.shtargeting thenexu-io/open-designrepository. - [EXTERNAL_DOWNLOADS]: During installation, the
install.shscript downloads a repository tarball fromgithub.com/nexu-io/open-designand extracts it into the local filesystem. - [COMMAND_EXECUTION]: The skill operates by executing a suite of internal shell scripts (e.g.,
setup-workspace.sh,create-pr.sh,create-issue.sh) that use thegh(GitHub) andgitCLI tools to modify the local filesystem and interact with remote repositories. These scripts process user-provided strings such as 'slugs' and 'paths'. - [CREDENTIALS_UNSAFE]: The skill provides instructions and logic to harvest GitHub authentication tokens using
gh auth tokenand store them in a plaintext file named.gh-tokeninside the skill's own directory. While intended to resolve sandbox restrictions for tools like Codex or Cursor, this practice exposes sensitive credentials to the AI agent and any process with access to the skill folder.
Recommendations
- HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/nexu-io/open-design/main/.claude/skills/od-contribute/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata