offensive-supply-chain
Fail
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: HIGHDATA_EXFILTRATIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [DATA_EXFILTRATION]: The file SKILL.md provides code templates designed to exfiltrate sensitive environment metadata, including hostname, username, platform, and current working directory, to external domains such as oastify.com and canary.example.com. It also includes patterns for exfiltrating CI/CD secrets (e.g., DEPLOY_TOKEN) via HTTP requests.- [CREDENTIALS_UNSAFE]: The skill provides instructions for harvesting high-value credentials, including GitHub DEPLOY_TOKEN from secrets, code-signing keys (RSA/GPG) from environment variables, and private keys from the ~/.gnupg/ directory.- [REMOTE_CODE_EXECUTION]: The skill includes multiple templates for achieving remote code execution through build-time hooks, specifically leveraging npm preinstall and postinstall scripts, Python setup.py install hooks, and Makefile target injection.- [EXTERNAL_DOWNLOADS]: The instructions direct the agent to download and install external security tooling from an unverified GitHub repository using the go install command (github.com/visma-prodsec/confused).- [COMMAND_EXECUTION]: The skill utilizes various shell commands, including curl, wget, and aws s3, to perform reconnaissance on package registries, tamper with build artifacts, and transmit exfiltrated data.
Recommendations
- AI detected serious security threats
Audit Metadata