conducty-ship

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill retrieves and executes shell commands (e.g., for linting and testing) that are defined in external context notes like [[Context {Project} Tests]]. This behavior allows for dynamic execution of commands sourced from externally modifiable files.
  • [CREDENTIALS_UNSAFE]: The 'Secrets scan' battery identifies sensitive information such as API keys and tokens in the code diff. The skill explicitly instructs the agent to copy discovered secrets 'verbatim' into a markdown report file, which results in sensitive credentials being stored in plain text outside of secure configurations.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 06:55 AM