huashu-nuwa

Fail

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Automated scans detected that the file examples/trump-perspective/references/research/03-expression-dna.md is infected with HttpRequest-inf [Susp]. This indicates the presence of suspicious network request patterns within the document structure.
  • [DATA_EXFILTRATION]: The file examples/trump-perspective/references/research/03-expression-dna.md contains a direct link to https://ijels.com/upload_document/issue_files/70IJELS-1042024-TheArt.pdf, which has been identified by scanners as a known botnet URL. Including such links in a skill's research data poses a critical risk of compromising the agent's environment or the user's system.
  • [COMMAND_EXECUTION]: The file examples/x-mastery-mentor/references/research/05-ai-tech-niche.md has been flagged as FileRepMalware, indicating that its content matches known malware signatures or has a very poor reputation from file scanning engines.
  • [REMOTE_CODE_EXECUTION]: The skill includes a shell script scripts/download_subtitles.sh that utilizes the yt-dlp tool to download external content based on user-supplied URLs. This execution path allows for arbitrary command execution if the external tool or the downloaded data is manipulated by an attacker.
  • [EXTERNAL_DOWNLOADS]: The primary operational flow of the skill (Phase 1: Multi-source information collection) involves automated agents performing large-scale data ingestion from untrusted external platforms such as X (Twitter), YouTube, and various blogs. This design creates a massive surface for Indirect Prompt Injection, where malicious instructions embedded in the ingested data could hijack the agent's behavior during the 'distillation' process and compromise any generated skills.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 25, 2026, 06:46 AM
Security Audit — agent-trust-hub — huashu-nuwa