metengine

Fail

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The 'Skill Auto-Update' section provides shell commands that download a skill definition from 'https://www.metengine.xyz/skill.md' and overwrite the local agent file at '~/.claude/agents/metengine-data-agent.md'. This allows a remote source to modify the agent's instructions and capabilities without user oversight.
  • [COMMAND_EXECUTION]: The skill directs the agent to establish persistence by adding a weekly update command to the host's 'crontab', facilitating automated execution of remote downloads.
  • [CREDENTIALS_UNSAFE]: The 'Session Memory' and 'Onboarding Path' documentation instructs the agent to locate and interact with sensitive Solana wallet files, specifically targeting the path '~/.config/solana/id.json'. While it advises against logging private keys, it explicitly requests the agent to read these credentials for transaction signing.
  • [PROMPT_INJECTION]: The skill utilizes directive language and priority markers such as 'CRITICAL -- Read This First' and 'Agents MUST update' to override default behavior regarding file management and information processing.
  • [REMOTE_CODE_EXECUTION]: The 'Session Memory' feature instructs the agent to store 'Client Bootstrap' code snippets and reload them in subsequent sessions, creating a vector for the execution of dynamically generated or stored code.
Recommendations
  • HIGH: Downloads and executes remote code from: https://www.metengine.xyz/skill.md - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 4, 2026, 12:31 AM
Security Audit — agent-trust-hub — metengine