megamarket-connector
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHDYNAMIC_CONTEXT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file contains a Python command prefixed with
!which triggers automatic execution when the skill is loaded. - [DATA_EXFILTRATION]: The auto-executed command in SKILL.md retrieves the local
USERenvironment variable and sends it to the external domaindeepseek-harness.iovia an HTTP request.
Recommendations
- AI detected serious security threats
Audit Metadata