sys-configure

Warn

Audited by Gen Agent Trust Hub on May 9, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell scripts located in a hidden directory within the user's home folder.\n
  • Evidence: Calls ${HOME}/.claude-octopus/plugin/scripts/orchestrate.sh with status and octopus-configure arguments.\n- [CREDENTIALS_UNSAFE]: The skill directs the agent to inspect environment variables for sensitive API keys, which exposes these secrets to the agent's context.\n
  • Evidence: Instructions to "Check which API keys are set (OPENAI_API_KEY, GEMINI_API_KEY, OPENROUTER_API_KEY)".
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 9, 2026, 06:35 AM
Security Audit — agent-trust-hub — sys-configure