huashu-nuwa

Fail

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires users to install the package alchaincyf/nuwa-skill via npx. This source is not recognized as a trusted vendor and is external to the stated author context of jwangkun.
  • [EXTERNAL_DOWNLOADS]: The research workflow in SKILL.md explicitly suggests downloading books and papers from shadow libraries such as Z-Library and LibGen, which are considered high-risk external sources.
  • [COMMAND_EXECUTION]: The skill utilizes the yt-dlp tool to download video content and transcripts, creating a command execution path using variables from external search results.
  • [PROMPT_INJECTION]: Personality template files (e.g., Steve Jobs, Elon Musk) include instructions intended to suppress safety disclaimers and limit the agent's meta-analysis, which can be used to bypass behavioral guardrails.
  • [PROMPT_INJECTION]: The skill maintains an indirect prompt injection vulnerability surface through its data collection process.
  • Ingestion points: Phase 1 in SKILL.md collects data from social media, articles, and transcripts.
  • Boundary markers: No delimiters or 'ignore instructions' warnings are present to isolate fetched data.
  • Capability inventory: The skill possesses the ability to spawn subagents, perform network operations, and write to the filesystem.
  • Sanitization: Fetched content is synthesized into instruction files without verification for malicious prompt injection patterns in the source material.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 24, 2026, 06:26 AM
Security Audit — agent-trust-hub — huashu-nuwa