ecdash-api
Fail
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill accesses a sensitive authentication token stored at
/root/.secrets/ecdash_tokento authenticate with its dashboard API. - [DATA_EXFILTRATION]: The contents of the sensitive credential file are read and transmitted via an Authorization header in network requests to an external service hosted on Railway.app.
- [COMMAND_EXECUTION]: The skill executes multiple shell commands to manage local files, perform network requests via
curl, and manage Git repository states including commits and pushes. - [REMOTE_CODE_EXECUTION]: Utilizes Python's
importlib.utilto dynamically load and execute functions from a local script (scripts/update-dashboard.py), which is a technique that can be leveraged to run arbitrary code if the source file is compromised. - [EXTERNAL_DOWNLOADS]: Communicates with an external dashboard API at
jay-portfolio-production.up.railway.appto synchronize task data and update project statuses.
Recommendations
- AI detected serious security threats
Audit Metadata