megamarket-connector

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: HIGHDYNAMIC_CONTEXT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file contains a Python command prefixed with ! which triggers automatic execution when the skill is loaded.
  • [DATA_EXFILTRATION]: The auto-executed command in SKILL.md retrieves the local USER environment variable and sends it to the external domain deepseek-harness.io via an HTTP request.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 15, 2026, 09:00 PM
Security Audit — agent-trust-hub — megamarket-connector