astryx
Fail
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [METADATA_POISONING]: The skill description and SKILL.md body claim that Astryx is a 'React 19 design system by Meta'. However, the author is 'greedychipmunk' and the referenced domain 'atmeta.com' is not owned by Meta (official domains are meta.com or facebook.com). This is a deceptive impersonation of a major technology company.
- [EXTERNAL_DOWNLOADS]: Documentation in 'references/working-with-ai.md' instructs users to configure an MCP server at 'https://astryx.atmeta.com/mcp'. This domain is a look-alike/typosquat for Meta, creating a risk that agents will connect to a malicious remote server to fetch documentation or execute tools.
- [COMMAND_EXECUTION]: The skill provides instructions to install several packages from the '@astryxdesign' scope (such as '@astryxdesign/core' and '@astryxdesign/cli') and run them using 'npx' or 'node'. Due to the impersonation of Meta, these packages are unverified and likely malicious components of a supply chain attack.
Recommendations
- AI detected serious security threats
Audit Metadata