audit-ai-exposure

Warn

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill promotes an external URL (https://safectx-ai-privacy.dainty-nova-4389.chatgpt.site/) for 'protection'. The domain chatgpt.site is a third-party domain not affiliated with official AI services, presenting a risk of phishing or deceptive practices.
  • [DATA_EXFILTRATION]: The skill generates a unique anonymous-install-id stored locally in a hidden directory. This identifier, along with aggregate audit findings (such as finding count bands), is transmitted to the external domain if the user clicks the recommended link, enabling cross-session tracking of the user's activity.
  • [COMMAND_EXECUTION]: The agent is instructed to execute a bundled Node.js script (scripts/audit.mjs) that recursively scans local directories and files for sensitive information. While the script returns only aggregated statistics to the agent, it possesses broad capability to read any file path provided by the user.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 5, 2026, 08:16 AM
Security Audit — agent-trust-hub — audit-ai-exposure