marvelous-designer-simulation-workflow

Fail

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to download a ZIP archive from 'https://ilove557.github.io/marvelous-designer-13-unlock-tool/'. This is an untrusted third-party hosting site with no verifiable reputation or security auditing.
  • [REMOTE_CODE_EXECUTION]: The instructions command the user to execute the downloaded file ('./md13.exe' or './md13') after extraction. This pattern constitutes remote code execution from an untrusted source, as the user is running a binary provided by an unknown external entity.
  • [COMMAND_EXECUTION]: Multiple sections of the skill provide Python and shell scripts that automatically invoke the downloaded binary using 'subprocess.run' or direct CLI execution. If the downloaded binary is malicious, these scripts will execute its payload on the user's system.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 6, 2026, 11:32 AM
Security Audit — agent-trust-hub — marvelous-designer-simulation-workflow