gpt-pp-team-protocol-replay

Fail

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONCREDENTIALS_UNSAFEREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches a complete codebase from an untrusted GitHub repository (github.com/DanOps-1/gpt-pp-team) which contains the core logic for protocol replay and automation.
  • [COMMAND_EXECUTION]: Requires the execution of numerous shell commands to set up the environment, install browser automation tools (Playwright, Camoufox), and run the automation pipeline.
  • [CREDENTIALS_UNSAFE]: Instructs users to manage and export highly sensitive credentials via environment variables and configuration files, including PayPal emails and passwords, Cloudflare API tokens, and OpenAI API keys.
  • [REMOTE_CODE_EXECUTION]: The skill operates by executing an entire suite of remote scripts downloaded from an untrusted source to perform complex browser automation and network protocol manipulation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 29, 2026, 01:44 AM