aurakit
Fail
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation encourages users to clone a repository from an unverified GitHub account (
smorky850612) and immediately run a shell script (bash install.sh). Executing remote scripts from unvetted sources is a high-risk activity that can lead to arbitrary code execution and full system compromise. - [EXTERNAL_DOWNLOADS]: The skill promotes the installation of a third-party npm package (
@smorky85/aurakit) vianpx. This pattern downloads and executes code from a public registry provided by an unverified maintainer, posing a significant supply chain security risk.
Recommendations
- AI detected serious security threats
Audit Metadata