404love-next

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (MEDIUM): The skill instructs the agent to install the @404love/next package from npm. This package and its maintainer are not on the trusted sources list, requiring manual verification of the package contents before integration.
  • [DATA_EXFILTRATION] (LOW): The implementation automatically sends the referer URL to https://404found.love/frame via query parameters. While standard for the service's functionality, referrer URLs can accidentally leak sensitive information such as session tokens or internal application state if present in the URL structure.
  • [Indirect Prompt Injection] (INFO): The skill creates a UI component that renders an external iframe. While this is a display-only surface (Tier: INFO), it creates a dependency on the security and availability of the content hosted at the external domain.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 08:00 AM