bdistill-behavioral-xray

Warn

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to install the bdistill Python package from a public registry. This package originates from an unverified community source rather than a trusted organization or well-known service.\n- [COMMAND_EXECUTION]: The skill commands include adding an MCP server using claude mcp add bdistill. This action modifies the agent's configuration to allow an external executable to function as a tool, providing it with persistent access to the agent's context.\n- [REMOTE_CODE_EXECUTION]: By registering an unverified third-party package as a Model Context Protocol (MCP) server, the skill enables the execution of arbitrary code from that package within the agent's operational environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 10, 2026, 12:32 AM
Security Audit — agent-trust-hub — bdistill-behavioral-xray