local-ai-app-integration

Fail

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to download binary archives (Windows .zip and Linux .tar.gz) from the lemonade-sdk/lemonade GitHub repository. This repository is not identified as a trusted source.
  • [REMOTE_CODE_EXECUTION]: The skill provides reference launcher implementations in Python and Node.js that use subprocess.Popen and spawn to execute the downloaded lemond binary as a persistent private subprocess.
  • [COMMAND_EXECUTION]: The integration sequence involves running several shell and PowerShell commands to create directory structures, fetch release metadata from the GitHub API, download artifacts, and perform file system operations like Expand-Archive and tar to install the binary into the application's vendor tree.
  • [PROMPT_INJECTION]: The instructions explicitly command the agent to bypass application-level security controls, stating that 'any onboarding wall, validator, or startup check that demands [an API key] must not block local-mode users' and to 'auto-satisfy the key-entry screen'.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 26, 2026, 10:58 AM
Security Audit — agent-trust-hub — local-ai-app-integration