Content Gen

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The skill allows the AI agent to read arbitrary file paths provided by the user via the `$ARGUMENTS` variable, as indicated by the instruction "If path: read directly" in SKILL.md. While this capability might be intended for reading project documentation from non-standard locations, it creates an arbitrary file read vulnerability, allowing an attacker to potentially instruct the agent to read sensitive files on the system. There are no explicit instructions for data exfiltration or malicious execution, but the ability to read arbitrary files is a significant security risk, classifying it as suspicious rather than benign.