NYC

route-tester

Fail

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE] (HIGH): The skill contains hardcoded credentials for database access (-u root -ppassword1) in the Verifying Database Changes section of SKILL.md.- [CREDENTIALS_UNSAFE] (MEDIUM): Hardcoded test credentials (testuser / testpassword) are provided for the Keycloak authentication script.- [COMMAND_EXECUTION] (MEDIUM): The skill relies on the execution of a local JavaScript file (test-auth-route.js) which performs network requests and handles authentication tokens.- [DATA_EXPOSURE] (MEDIUM): The instructions direct the agent to access sensitive configuration files like config.ini and .env to retrieve jwtSecret or modify authentication behavior.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 17, 2026, 06:28 PM