letta-configuration

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: CRITICALCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill includes hardcoded default credentials intended for local development environments, such as postgresql://letta:letta@localhost/letta in references/environment_variables.md and scripts/generate_env.py. Documentation provides guidance on securing these values for production use.
  • [COMMAND_EXECUTION]: The scripts/generate_env.py script performs file system writes to create .env files. This is a functional requirement for the skill to assist users in configuring their local or containerized environments.
  • [DATA_EXFILTRATION]: Administrative scripts (scripts/setup_provider.py and scripts/validate_provider.py) facilitate the registration of API keys by sending them to a locally hosted Letta server at http://localhost:8283. This local network communication is the intended mechanism for provider setup.
  • [EXTERNAL_DOWNLOADS]: The skill references the vendor's official package @letta-ai/letta-client in scripts/basic_config.ts. This dependency is required for the skill to function within the vendor's ecosystem.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 14, 2026, 07:46 PM
Security Audit — agent-trust-hub — letta-configuration