logo-creator
Fail
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [CREDENTIALS_UNSAFE]: The scripts
scripts/remove_bg.pyandscripts/vectorize.pyattempt to access and read the user's shell configuration file (~/.zshrc) to harvest API keys (REMOVE_BG_API_KEY and RECRAFT_API_KEY) if they are not already set in the environment. Accessing shell profiles is a high-risk behavior as these files typically contain various sensitive environment variables and credentials. - [COMMAND_EXECUTION]: The skill performs shell command execution using subprocess.run to call grep for file searching and curl for API communication and file downloads.
- [DATA_EXFILTRATION]: The skill transmits local image data to external third-party APIs (remove.bg and external.api.recraft.ai) to fulfill its logo processing functions. While this is the stated purpose of the skill, it involves sending user files to external servers.
Recommendations
- AI detected serious security threats
Audit Metadata