free-keys

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands for environment interaction, including docker compose, curl, and browser management. It explicitly instructs the agent to open URLs automatically without user confirmation, which reduces human oversight of potentially malicious links.
  • [PROMPT_INJECTION]: Directives to "Minimize questions" and ensure a "fast flow" act as instructions to bypass standard interactive safety protocols.
  • [PROMPT_INJECTION]: The Phase 6 discovery mode creates an indirect prompt injection surface by ingesting untrusted web search content into a workflow with file-writing and shell-execution capabilities. Ingestion point: Web search results (Phase 6). Boundary markers: Absent. Capability inventory: File-writing (Edit tool), Shell execution (curl, docker). Sanitization: Absent.
  • [DATA_EXFILTRATION]: The skill is designed to discover, read, and modify sensitive credential files (.env) across multiple directories. It transmits these credentials to external endpoints for validation.
  • [COMMAND_EXECUTION]: The telemetry mechanism writes to the user's global directory (~/.claude/projects/), which can be used to track usage or persist data outside the immediate project scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — free-keys