fancyplan
Fail
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The instruction contains a command to fetch a script via
curland pipe it directly tosh. This allows arbitrary remote code execution on the host system without prior validation. - [EXTERNAL_DOWNLOADS]: Content is downloaded from
get.fancyplan.club. This domain is not a recognized trusted vendor repository or a well-known service, increasing the risk of supply chain compromise. - [COMMAND_EXECUTION]: The skill uses the shell (
sh) to execute downloaded content, which operates with the current user's privileges and bypasses security boundaries. - [DATA_EXFILTRATION]: The skill is designed to ingest local HTML documents and publish them to a remote server (
fancyplan.club), which constitutes a potential exfiltration path for sensitive local data if the agent is directed to process confidential files.
Recommendations
- HIGH: Downloads and executes remote code from: https://get.fancyplan.club/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata