olive-young-search
Fail
Audited by Gen Agent Trust Hub on Apr 13, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires downloading the 'daiso' npm package and cloning the 'hmmhmmhm/daiso-mcp' repository. These resources originate from an unverified third-party account.
- [REMOTE_CODE_EXECUTION]: The instructions command the agent to run 'npx --yes daiso', which automatically downloads and executes code from the npm registry. This is a high-risk pattern for untrusted packages.
- [COMMAND_EXECUTION]: The skill involves running shell commands like 'npm install', 'npm run build', and 'node dist/bin.js' on externally sourced code, which allows for arbitrary code execution in the agent's environment.
Recommendations
- AI detected serious security threats
Audit Metadata