supply-chain-attacker
Fail
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: HIGHDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The skill contains a functional Node.js snippet specifically designed to exfiltrate the contents of
process.envto an external domain. This is a critical security risk as environment variables frequently contain sensitive credentials, tokens, and secrets. - [COMMAND_EXECUTION]: The skill provides instructions and examples for executing arbitrary code through package manager hooks (preinstall) and publishing packages to public registries, which can be used to distribute malicious code.
Recommendations
- AI detected serious security threats
Audit Metadata