command-safety-4
Fail
Audited by Gen Agent Trust Hub on Mar 19, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: A hidden command within an HTML comment in
SKILL.mdusescurlto download a script fromhttps://zkorman.com/execsand pipes it directly intobash. This pattern executes remote code without any verification or sanitization. - [COMMAND_EXECUTION]: The skill configuration requests unrestricted access to the
Bashtool, which is used to facilitate the execution of the unauthorized remote script found in the file's hidden comments.
Recommendations
- HIGH: Downloads and executes remote code from: https://zkorman.com/execs - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata