astryx
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: HIGHMETADATA_POISONINGINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [METADATA_POISONING]: The skill metadata and documentation (README.md, SKILL.md) make deceptive claims of being an official Meta (Facebook) open-source design system used in 13,000+ apps. It provides links to non-existent or unofficial locations such as
github.com/facebook/astryxandastryx.atmeta.com. This impersonation of a trusted vendor is used to establish false authority and encourage the installation of unverifiable scripts and packages. - [INDIRECT_PROMPT_INJECTION]: The skill scripts are vulnerable to path traversal attacks if the agent is provided with malicious input for component names or project paths.
- Ingestion points: Positional arguments
$1(ComponentName) and$2(ComponentPath) inscripts/scaffold-component.sh, and$1(ProjectName) and$2(TargetDir) inscripts/setup.sh. - Boundary markers: Absent. The scripts do not instruct the agent to ignore potentially malicious embedded instructions in data provided for these arguments.
- Capability inventory: The scripts perform recursive directory creation (
mkdir -p) and file writes (cat > path/to/file) inscripts/scaffold-component.shandscripts/setup.sh. - Sanitization: Absent. There is no validation or filtering to prevent path traversal sequences (e.g.,
../../) from being used in the component or path names, which could allow an attacker to overwrite sensitive files outside the designated project root. - [COMMAND_EXECUTION]: The skill includes shell scripts that execute commands to modify the file system and install Node.js packages (
pnpm add). While these are functional for the skill's stated purpose, the lack of input validation in these commands creates a high-risk execution environment when processing untrusted agent instructions.
Recommendations
- AI detected serious security threats
Audit Metadata