route-tester
Fail
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE] (HIGH): The skill contains hardcoded credentials for database access (
-u root -ppassword1) in theVerifying Database Changessection ofSKILL.md.- [CREDENTIALS_UNSAFE] (MEDIUM): Hardcoded test credentials (testuser/testpassword) are provided for the Keycloak authentication script.- [COMMAND_EXECUTION] (MEDIUM): The skill relies on the execution of a local JavaScript file (test-auth-route.js) which performs network requests and handles authentication tokens.- [DATA_EXPOSURE] (MEDIUM): The instructions direct the agent to access sensitive configuration files likeconfig.iniand.envto retrievejwtSecretor modify authentication behavior.
Recommendations
- AI detected serious security threats
Audit Metadata