bookstrap-status

Fail

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill includes hardcoded credentials in the Bash command used to interact with the database. Specifically, it uses --user root --pass root in the surreal sql command sequence.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute multiple shell commands, including:
  • Health checks using curl against localhost:2665.
  • Database interaction using the surreal CLI tool.
  • File system checks for BRD.md using shell conditionals.
  • [DATA_EXPOSURE]: The skill accesses project files like BRD.md and bookstrap.config.json to extract project metadata and configuration details.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 16, 2026, 08:06 AM