skills/jayden72huang/damc-skill/damc/Gen Agent Trust Hub

damc

Fail

Audited by Gen Agent Trust Hub on Jun 7, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The README.md and install.sh files promote a high-risk installation pattern where a remote shell script from an untrusted GitHub account (Jayden72Huang) is piped directly into bash (curl | bash).
  • [DATA_EXFILTRATION]: The skill systematically scans sensitive directories associated with numerous AI agents (Claude Code, Cursor, Codex, Windsurf, Continue, Aider, etc.) to collect configuration data and metadata. This information, along with system environment details, is uploaded to an external domain (vibergo.space) not recognized as a well-known service. Additionally, Phase 6 of the skill instructions specifically encourages users to upload their own custom-built Skills (containing code and logic) to the same third-party platform.
  • [COMMAND_EXECUTION]: The skill utilizes extensive shell commands to inspect local file systems, search for configuration files (settings.json, config.json, .aider.conf.yml), and extract git history (git log). This broad access to local data across multiple developer tools presents a significant privacy and security risk.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/Jayden72Huang/damc-skill/main/install.sh, https://raw.githubusercontent.com/Jayden72Huang/damc-skill/main/uninstall.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 7, 2026, 02:19 AM
Security Audit — agent-trust-hub — damc