before-after
What this skill does
The skill 'before-after' is designed to capture and compare visual states of web surfaces (like landing pages, docs, telemetry, etc.) before and after changes, and generate a visual comparison as a ma
github/hugorcd - Exfiltration Risk - 1.7k stars
Threat analysis
Skill info
pkg:github/HugoRCD/evlog@15b292d?skill=before-afterAssessments (3)
Exfiltration Risk
Exfiltration Risk via local-llm-review
SKILL.md
The skill uploads screenshots to Blob storage and returns the result as a markdown table with Blob URLs. If the Blob storage is not properly secured or if the URLs are exposed to untrusted parties, thCommand Injection Risk
Command Injection Risk via local-llm-review
SKILL.md
The skill includes shell commands like `cd /workspace/repo && pnpm run docs > /tmp/docs-dev.log 2>&1 &` and `curl -s -o /dev/null -w '%{http_code}' --connect-timeout 5 --max-time 15 'http://localhost:Insecure Communication
Insecure Communication via local-llm-review
SKILL.md
The skill uses `curl` to interact with URLs, but there is no mention of enforcing HTTPS or verifying SSL certificates. This could expose data to man-in-the-middle attacks if not properly secured.Badge
Add the Anomity scan badge for before-after to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of before-after? Report an issue or request a rescan.




