skills/onmax/skills/vitehub-drop/Gen Agent Trust Hub

vitehub-drop

Warn

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill provides instructions to upload local files from the agent's environment to an external endpoint (https://drop.vitehub.dev/api/files). This behavior exfiltrates local data to a third-party service and results in the file being hosted at a public URL, which represents a potential data exposure and privacy risk.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands (curl and jq) to perform file uploads. The command structure allows for the transmission of any file accessible to the agent to an external API endpoint.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 25, 2026, 12:52 AM
Security Audit — agent-trust-hub — vitehub-drop