404love-next
Warn
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [EXTERNAL_DOWNLOADS] (MEDIUM): The skill instructs the agent to install the
@404love/nextpackage from npm. This package and its maintainer are not on the trusted sources list, requiring manual verification of the package contents before integration. - [DATA_EXFILTRATION] (LOW): The implementation automatically sends the
refererURL tohttps://404found.love/framevia query parameters. While standard for the service's functionality, referrer URLs can accidentally leak sensitive information such as session tokens or internal application state if present in the URL structure. - [Indirect Prompt Injection] (INFO): The skill creates a UI component that renders an external iframe. While this is a display-only surface (Tier: INFO), it creates a dependency on the security and availability of the content hosted at the external domain.
Audit Metadata