security-secrets

Warn

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/scan-all.sh uses eval to execute conditions and directly invokes other skill scripts from hardcoded paths in the user's home directory (e.g., ~/.config/opencode/skill/security-ai-keys/scripts/scan.sh). This assumes a specific filesystem structure and relies on the presence of other external scripts which may have been modified or could be malicious. While intended for a modular architecture, cross-skill script execution from user-writable paths introduces a risk of executing unintended or untrusted code if those paths are compromised.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 02:10 AM
Security Audit — agent-trust-hub — security-secrets