huashu-nuwa
Fail
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires users to install the package
alchaincyf/nuwa-skillvianpx. This source is not recognized as a trusted vendor and is external to the stated author context of jwangkun. - [EXTERNAL_DOWNLOADS]: The research workflow in
SKILL.mdexplicitly suggests downloading books and papers from shadow libraries such asZ-LibraryandLibGen, which are considered high-risk external sources. - [COMMAND_EXECUTION]: The skill utilizes the
yt-dlptool to download video content and transcripts, creating a command execution path using variables from external search results. - [PROMPT_INJECTION]: Personality template files (e.g., Steve Jobs, Elon Musk) include instructions intended to suppress safety disclaimers and limit the agent's meta-analysis, which can be used to bypass behavioral guardrails.
- [PROMPT_INJECTION]: The skill maintains an indirect prompt injection vulnerability surface through its data collection process.
- Ingestion points:
Phase 1inSKILL.mdcollects data from social media, articles, and transcripts. - Boundary markers: No delimiters or 'ignore instructions' warnings are present to isolate fetched data.
- Capability inventory: The skill possesses the ability to spawn subagents, perform network operations, and write to the filesystem.
- Sanitization: Fetched content is synthesized into instruction files without verification for malicious prompt injection patterns in the source material.
Recommendations
- AI detected serious security threats
Audit Metadata