stacktree-publish
Fail
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a bash script (
scripts/publish.sh) to transmit generated HTML artifacts to the Stacktree API usingcurl. This is a core part of its intended functionality for publishing user-generated content. - [EXTERNAL_DOWNLOADS]: The skill makes network requests to
api.stacktr.eefor publishing content andstabledomains.devfor optional domain registration. These are vendor-owned resources and part of the skill's primary purpose. Automated scanner flags for these domains likely stem from their hosting nature (similar to how generic paste sites are flagged), but no malicious patterns were found in the skill's implementation of these services. - [DATA_EXPOSURE]: The skill contains a PII (Personally Identifiable Information) scanner that defaults to 'block' mode. It explicitly searches for and blocks the upload of sensitive data like SSNs, credit cards, and common API key prefixes (e.g., AWS, GitHub, Slack) to prevent accidental data exfiltration.
- [CREDENTIALS_SAFE]: The skill instructs users to manage their
STACKTREE_API_KEYvia environment variables (.envor shell profiles) rather than hardcoding them, which follows security best practices.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 15 malicious URL(s) - DO NOT USE
Audit Metadata