astryx
Warn
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes shell scripts (
scripts/setup.shandscripts/scaffold-component.sh) that perform file system operations, directory creation, and configuration updates. These scripts are intended to be run locally to initialize projects and generate component boilerplate, writing files such astsconfig.jsonandApp.tsx. - [EXTERNAL_DOWNLOADS]: The
setup.shscript installs several Node.js packages from public registries, including the vendor's own packages (@astryxdesign/core,@astryxdesign/cli) and standard dependencies like React and TypeScript. - [PROMPT_INJECTION]: The skill contains deceptive documentation and metadata designed to mislead the agent and the user about its origin and security posture. It falsely claims to be 'Meta's open source design system' and 'proven across 13,000+ apps,' using unverifiable links to non-existent GitHub repositories (e.g.,
facebook/astryx) and deceptive domains (e.g.,astryx.atmeta.com). This impersonation of a well-known organization is a deceptive technique used to establish unearned trust and bypass safety scrutiny.
Audit Metadata