character-consistency
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill performs network requests to
ai-hive.iclip.cn, which is an external domain not included in the standard whitelist. - [DATA_EXPOSURE_AND_EXFILTRATION]: The script reads API keys from a local configuration file at
~/.ai-hive/config.jsonand transmits them in HTTP headers to the service domain. - [DATA_EXPOSURE_AND_EXFILTRATION]: The
upload_mediafunction reads local files provided by the user and uploads them to dynamic URLs provided by the external API at runtime. - [DYNAMIC_EXECUTION]: The
initcommand useswebbrowser.opento launch the system's default browser, navigating to a help URL to facilitate API key configuration.
Audit Metadata