vitehub-drop
Warn
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: MEDIUMDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill provides instructions to upload local files from the agent's environment to an external endpoint (
https://drop.vitehub.dev/api/files). This behavior exfiltrates local data to a third-party service and results in the file being hosted at a public URL, which represents a potential data exposure and privacy risk. - [COMMAND_EXECUTION]: The skill utilizes shell commands (
curlandjq) to perform file uploads. The command structure allows for the transmission of any file accessible to the agent to an external API endpoint.
Audit Metadata