supply-chain-attacker

Fail

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill contains a functional Node.js snippet specifically designed to exfiltrate the contents of process.env to an external domain. This is a critical security risk as environment variables frequently contain sensitive credentials, tokens, and secrets.
  • [COMMAND_EXECUTION]: The skill provides instructions and examples for executing arbitrary code through package manager hooks (preinstall) and publishing packages to public registries, which can be used to distribute malicious code.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 20, 2026, 09:07 AM
Security Audit — agent-trust-hub — supply-chain-attacker