python

Fail

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The mirrored HTML file 'references/cursorrules.org-mypy-cursor-mdc-file.html' contains a hyperlink to 'https://loveanddeepspace.net/', which is currently blacklisted as a malicious domain. This poses a risk if an agent or user follows the link.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests installing and using various third-party packages including ruff, black, mypy, pyright, pytest, httpx, sqlalchemy, and others. While these are reputable libraries, the skill promotes external code execution via installation.
  • [PROMPT_INJECTION]: The logic in SKILL.md and its references defines agent behavior for code review and refactoring. No explicit adversarial overrides or safety bypass instructions were found.
  • [NO_CODE]: The skill package is composed entirely of configuration files, markdown documentation, and mirrored web pages. It does not include executable scripts or binaries of its own.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 21, 2026, 07:18 AM
Security Audit — agent-trust-hub — python