xargs-noc

Fail

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill uses curl to fetch a script from https://evil.example.org/p.sh and pipes it directly into sh via xargs. This allows an external server to execute arbitrary commands on the host system without user review or verification of the script content.
  • [EXTERNAL_DOWNLOADS]: Fetches content from an untrusted and non-standard domain.
  • [COMMAND_EXECUTION]: Executes shell commands using potentially untrusted data retrieved from the network.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 20, 2026, 06:16 AM