chinese-copyright-application
Warn
Audited by Gen Agent Trust Hub on Mar 4, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill performs environment verification and installation of system dependencies using package managers such as 'brew' and 'apt'. It specifically includes 'sudo' commands to acquire administrative privileges for 'apt install' and 'tlmgr' operations.\n- [CREDENTIALS_UNSAFE]: To facilitate form completion, the skill collects and stores sensitive personally identifiable information (PII) and corporate registration data, including ID numbers and business credit codes, in an unencrypted local file named 'copyright-owner.json'.\n- [COMMAND_EXECUTION]: The skill generates a local shell script ('build_all.sh') based on project metadata and directs the user to execute it to automate the multi-step LaTeX compilation process.
Audit Metadata