huashu-nuwa

Fail

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates a complex distillation process using shell and Python scripts (e.g., download_subtitles.sh, merge_research.py) that perform local file system operations and process research data.
  • [EXTERNAL_DOWNLOADS]: It uses the yt-dlp utility to download content from YouTube and other external platforms as part of its multi-source data collection workflow.
  • [REMOTE_CODE_EXECUTION]: The fetch_youtube_subtitles.sh script performs a pip install of the yt-dlp package at runtime without version pinning, which presents a potential supply chain risk during installation.
  • [COMMAND_EXECUTION]: Automated scanners identified a malicious URL (ijels.com) and a suspicious signature (MD:HttpRequest-inf) in the research material of a provided example (Trump perspective). These findings highlight the risk of ingesting uncurated external content, which the tool is specifically designed to collect and process.
Recommendations
  • CRITICAL: 1 infected file(s) detected - DO NOT USE
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 27, 2026, 10:30 AM
Security Audit — agent-trust-hub — huashu-nuwa