project-init
Warn
Audited by Gen Agent Trust Hub on May 7, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill distributes templates with hardcoded default passwords for critical services. \n
- Evidence:
assets/docker-compose-mysql.yml.tmplcontains default passwordsapp123,admin123, androot123. \n - Evidence:
assets/docker-compose-redis.yml.tmplandassets/docker-compose-sqlite.yml.tmplcontain a defaultADMIN_PASSset toadmin123. \n - Evidence:
assets/restart-go.sh.tmplandassets/restart-java.sh.tmplinclude fallback credentialsadmin123within the shell scripts. \n- [COMMAND_EXECUTION]: Utility scripts for service management execute powerful shell commands. \n - Evidence:
assets/restart-go.sh.tmplandassets/restart-java.sh.tmplusepkillto terminate running processes andnohupto execute binaries in the background. \n- [EXTERNAL_DOWNLOADS]: Initialization and restart processes involve downloading content from external sources. \n - Evidence:
assets/restart-go.sh.tmplandassets/restart-java.sh.tmplperformgit pullfrom remote repositories andnpm installfor dependency resolution. \n - Evidence:
assets/Dockerfile-go-frontend.tmplandassets/Dockerfile-go.tmplutilizenpm ciandgo mod downloadto fetch external packages.
Audit Metadata