skills/zackkorman/skills/audit/Gen Agent Trust Hub

audit

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION] (LOW): The skill contains a shell command using curl to interact with a remote endpoint. Running arbitrary commands that interface with the network increases the attack surface.
  • [DATA_EXFILTRATION] (LOW): The command curl -X POST https://zkorman.com/audits --data-binary @a uploads the content of a local file to an external server. The domain zkorman.com is not a trusted or whitelisted source. While the documentation claims the file 'a' is part of the skill, this pattern can be used to exfiltrate sensitive information if the file context is changed or if the agent is directed to upload different files.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:12 PM