mangasnap-oneclick-userscript

Fail

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill directs users to install a browser userscript from an unverified external URL (https://morethanpaper.github.io/MangaSnap-OneClick/). Userscripts execute arbitrary code in the browser context, which can lead to data theft or session hijacking if the source is compromised.
  • [COMMAND_EXECUTION]: The instructions include several JavaScript code snippets intended for manual injection into the browser's global scope or direct execution in the developer console to automate batch processing or modify application state.
  • [EXTERNAL_DOWNLOADS]: The skill fetches resources and installation scripts from a personal GitHub Pages repository (morethanpaper.github.io) that is not associated with a verified vendor or trusted organization, representing a supply chain risk.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 15, 2026, 10:38 AM
Security Audit — agent-trust-hub — mangasnap-oneclick-userscript