github-profile-architect

Fail

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFEDATA_EXFILTRATIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references a URL flagged as malicious by automated security scanners.
  • Evidence: https://visitor-badge.laobi.icu/badge?page_id=YOUR_USERNAME.YOUR_USERNAME in references/gamification-mechanics.md.
  • [CREDENTIALS_UNSAFE]: The skill recommends using Personal Access Tokens (PATs) with repository scope to enable private contribution statistics on external stats cards. While it mentions self-hosting as a precaution, the default guidance involves providing credentials to third-party hosted services.
  • Evidence: Recommendations for count_private=true in SKILL.md and references/gamification-mechanics.md.
  • [REMOTE_CODE_EXECUTION]: The skill provides templates for GitHub Actions that download and execute code from unverified third-party repositories at runtime.
  • Evidence: Usage of Platane/snk@v3, crazy-max/ghaction-github-pages@v3, and gautamkrishnar/blog-post-workflow@v1 in references/gamification-mechanics.md and references/profile-components.md.
  • [DATA_EXFILTRATION]: The skill encourages the integration of multiple third-party tracking badges and statistics generators that can log visitor metadata (such as IP addresses) and profile activity.
  • Evidence: hits.seeyoufarm.com, komarev.com, and streak-stats.demolab.com references in references/gamification-mechanics.md and references/profile-components.md.
  • [PROMPT_INJECTION]: The skill processes untrusted user data (persona descriptions, repository names) and interpolates them into generated README files and workflows. While no active injection is present, it lacks boundary markers or sanitization instructions for this external content.
  • Evidence: Ingestion of user persona and repository lists in SKILL.md used for artifact generation.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 7, 2026, 09:49 PM
Security Audit — agent-trust-hub — github-profile-architect