github-proxy

Warn

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill documentation and helper script facilitate downloading code and resources from GitHub via untrusted third-party proxy services.
  • Evidence: SKILL.md provides instructions to prefix GitHub URLs with https://githubproxy.cc/ for cloning and downloading files.
  • Evidence: scripts/convert_url.py hardcodes https://githubproxy.cc and https://ghfast.top as proxy destinations.
  • Impact: Downloads through untrusted intermediaries can result in the delivery of tampered or malicious code if the proxy service is compromised or malicious.
  • [DATA_EXFILTRATION]: The skill routes network requests through non-whitelisted external domains.
  • Evidence: All GitHub requests are directed to githubproxy.cc or ghfast.top when using the skill's methods.
  • Impact: This exposes the user's repository access patterns and potentially sensitive metadata to the operators of these third-party services.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 19, 2026, 06:32 AM
Security Audit — agent-trust-hub — github-proxy