huashu-nuwa
Fail
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: CRITICALCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill orchestrates a complex distillation process using shell and Python scripts (e.g., download_subtitles.sh, merge_research.py) that perform local file system operations and process research data.
- [EXTERNAL_DOWNLOADS]: It uses the yt-dlp utility to download content from YouTube and other external platforms as part of its multi-source data collection workflow.
- [REMOTE_CODE_EXECUTION]: The fetch_youtube_subtitles.sh script performs a pip install of the yt-dlp package at runtime without version pinning, which presents a potential supply chain risk during installation.
- [COMMAND_EXECUTION]: Automated scanners identified a malicious URL (ijels.com) and a suspicious signature (MD:HttpRequest-inf) in the research material of a provided example (Trump perspective). These findings highlight the risk of ingesting uncurated external content, which the tool is specifically designed to collect and process.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata