olive-young-search

Fail

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires downloading the 'daiso' npm package and cloning the 'hmmhmmhm/daiso-mcp' repository. These resources originate from an unverified third-party account.
  • [REMOTE_CODE_EXECUTION]: The instructions command the agent to run 'npx --yes daiso', which automatically downloads and executes code from the npm registry. This is a high-risk pattern for untrusted packages.
  • [COMMAND_EXECUTION]: The skill involves running shell commands like 'npm install', 'npm run build', and 'node dist/bin.js' on externally sourced code, which allows for arbitrary code execution in the agent's environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Apr 13, 2026, 01:00 AM
Security Audit — agent-trust-hub — olive-young-search