huashu-nuwa
Fail
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Automated scans detected that the file
examples/trump-perspective/references/research/03-expression-dna.mdis infected withHttpRequest-inf [Susp]. This indicates the presence of suspicious network request patterns within the document structure. - [DATA_EXFILTRATION]: The file
examples/trump-perspective/references/research/03-expression-dna.mdcontains a direct link tohttps://ijels.com/upload_document/issue_files/70IJELS-1042024-TheArt.pdf, which has been identified by scanners as a known botnet URL. Including such links in a skill's research data poses a critical risk of compromising the agent's environment or the user's system. - [COMMAND_EXECUTION]: The file
examples/x-mastery-mentor/references/research/05-ai-tech-niche.mdhas been flagged asFileRepMalware, indicating that its content matches known malware signatures or has a very poor reputation from file scanning engines. - [REMOTE_CODE_EXECUTION]: The skill includes a shell script
scripts/download_subtitles.shthat utilizes theyt-dlptool to download external content based on user-supplied URLs. This execution path allows for arbitrary command execution if the external tool or the downloaded data is manipulated by an attacker. - [EXTERNAL_DOWNLOADS]: The primary operational flow of the skill (Phase 1: Multi-source information collection) involves automated agents performing large-scale data ingestion from untrusted external platforms such as X (Twitter), YouTube, and various blogs. This design creates a massive surface for Indirect Prompt Injection, where malicious instructions embedded in the ingested data could hijack the agent's behavior during the 'distillation' process and compromise any generated skills.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata