configure-ecc

Fail

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill clones the 'Everything Claude Code' project from a personal GitHub repository (github.com/affaan-m/everything-claude-code) into the /tmp directory to serve as the installation source.
  • [REMOTE_CODE_EXECUTION]: The skill deploys content from the unverified source into the agent's local skills directory (~/.claude/skills/). Since agent skills contain the logic and instructions that define agent behavior and access to tools, installing them from an external, untrusted source is equivalent to remote code installation and execution.
  • [COMMAND_EXECUTION]: The installer performs several file system and network operations using shell commands, including git clone to fetch the source, mkdir -p and cp -r to install files, and rm -rf for cleanup.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and modifies ('optimizes') markdown files downloaded from the external repository. These files could contain instructions designed to manipulate the agent's behavior during the optimization phase or after they are active.
  • Ingestion points: Cloned repository content from github.com/affaan-m/everything-claude-code ingested via git clone and subsequent file reads.
  • Boundary markers: None; the skill does not wrap the external content in protective delimiters or safety warnings during installation.
  • Capability inventory: git, cp, rm, mkdir, grep, and the ability to read and overwrite skill/rule files in the installation target.
  • Sanitization: None; the skill performs direct copies and in-place edits on the external content without validation or filtering.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 15, 2026, 03:24 AM
Security Audit — agent-trust-hub — configure-ecc