letta-configuration
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: CRITICALCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill includes hardcoded default credentials intended for local development environments, such as
postgresql://letta:letta@localhost/lettainreferences/environment_variables.mdandscripts/generate_env.py. Documentation provides guidance on securing these values for production use. - [COMMAND_EXECUTION]: The
scripts/generate_env.pyscript performs file system writes to create.envfiles. This is a functional requirement for the skill to assist users in configuring their local or containerized environments. - [DATA_EXFILTRATION]: Administrative scripts (
scripts/setup_provider.pyandscripts/validate_provider.py) facilitate the registration of API keys by sending them to a locally hosted Letta server athttp://localhost:8283. This local network communication is the intended mechanism for provider setup. - [EXTERNAL_DOWNLOADS]: The skill references the vendor's official package
@letta-ai/letta-clientinscripts/basic_config.ts. This dependency is required for the skill to function within the vendor's ecosystem.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata