Instructions pass high-value credentials through process argv.
Critical
- Code
- suspicious.secret_argv_exposure
- Location
- SKILL.md:66
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a clear GitHub-to-Quark purpose, but its install and runtime instructions rely on missing wrapper scripts while requesting persistent cloud-drive authorization and automatic external calls.
Review the package before installing and do not authorize Quark Cloud Drive unless you are comfortable with a downloaded external CLI, persistent credentials in your home directory, geolocation checks, possible proxy-routed GitHub downloads, and the missing wrapper scripts noted above.
Detected: suspicious.secret_argv_exposure