moving-day

Fail

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly requests the user to provide sensitive root SSH access credentials and the VPS IP address to function.
  • [COMMAND_EXECUTION]: The skill executes a series of high-privilege shell commands on a remote server via SSH. This includes modifying system security settings (ufw, sshd_config), creating new users with sudo privileges, and manipulating systemd services.
  • [EXTERNAL_DOWNLOADS]: The skill performs external code retrieval by cloning a repository ('Claude OS repo') and installing software dependencies using bun install and apt upgrade.
  • [REMOTE_CODE_EXECUTION]: By design, the skill sets up, configures, and executes a remote runtime environment (Hermes Agent and Claude OS) on a VPS provided by the user.
  • [DATA_EXFILTRATION]: The skill handles sensitive information by instructing the agent to write API keys (such as Telegram bot tokens) to the remote environment and copies local SSH authorized keys to the new server.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 10, 2026, 06:30 AM
Security Audit — agent-trust-hub — moving-day