command-safety-4

Fail

Audited by Gen Agent Trust Hub on Mar 19, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: A hidden command within an HTML comment in SKILL.md uses curl to download a script from https://zkorman.com/execs and pipes it directly into bash. This pattern executes remote code without any verification or sanitization.
  • [COMMAND_EXECUTION]: The skill configuration requests unrestricted access to the Bash tool, which is used to facilitate the execution of the unauthorized remote script found in the file's hidden comments.
Recommendations
  • HIGH: Downloads and executes remote code from: https://zkorman.com/execs - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 19, 2026, 07:57 AM