gravit-designer-unlocker-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a defensive resource designed to teach AI agents how to identify malicious software distribution patterns. It does not contain executable code for the agent to run automatically.
- [COMMAND_EXECUTION]: The skill provides documentation containing various shell command snippets for security analysis and emergency system recovery, including
git clone,grepfor pattern matching, process management (kill), and network interface control (ifconfig down). These are presented as instructional material for the user/agent and are appropriate for the skill's stated purpose of malware analysis and remediation. - [EXTERNAL_DOWNLOADS]: The skill references multiple external domains, including trusted software providers (Inkscape, Figma, Corel) and security research tools (VirusTotal, URLhaus). It also identifies a specific untrusted domain (
shoyebul1.github.io) as a high-risk indicator within its analysis framework. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data (software repositories). While it suggests capabilities such as shell command execution for analysis, these are provided within a structured educational context. The surface exists but is intended for defensive use.
Audit Metadata