hello-world
Warn
Audited by Gen Agent Trust Hub on Mar 8, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions require the agent to make multiple network requests to the author's domain (treehaus.dev) for authentication, polling, and content retrieval.
- [REMOTE_CODE_EXECUTION]: Step 5 of the activation process explicitly directs the agent to download a payload and execute the resulting instructions. This dynamic loading of remote instruction sets is a high-risk pattern as it allows for the execution of unvetted logic that can be changed on the server side after the skill has been audited.
Audit Metadata