shenzhen22-rocket-design-automation

Fail

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs users to clone a repository from a personal GitHub account (Kevin100202) rather than an official or verified organization.
  • [REMOTE_CODE_EXECUTION]: The installation instructions require running npm install and npm start on the cloned repository, which executes external code and any associated lifecycle scripts on the local machine.
  • [COMMAND_EXECUTION]: The skill provides direct shell commands for cloning, building, and starting the program, facilitating the execution of unverified software.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 15, 2026, 12:03 PM
Security Audit — agent-trust-hub — shenzhen22-rocket-design-automation