skills/kunchenguid/lavish-axi/lavish/Gen Agent Trust Hub

lavish

Warn

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill is designed to execute the lavish-axi package using npx -y, which downloads and runs code from the NPM registry. This method of invocation does not specify a package version, potentially allowing for the execution of newer, unverified versions of the tool.
  • [COMMAND_EXECUTION]: The workflow relies heavily on shell command execution, including npx, node, and direct calls to lavish-axi. It includes fallback logic to locate local or global installations using npm root and npm root -g.
  • [EXTERNAL_DOWNLOADS]: In addition to downloading the main CLI tool, the skill fetches specific content via npx -y lavish-axi playbook <id> and npx -y lavish-axi design, which retrieve focused guidance and design snippets from remote sources.
  • [DATA_EXFILTRATION]: The skill provides a share command that uploads local artifacts to https://ht-ml.app. The instructions note that these shares are public by default, which presents a risk of sensitive information contained within the generated artifacts being exposed to unauthorized third parties.
  • [PROMPT_INJECTION]: The skill includes instructions to conceal specific agent activities from the user: "Do not tell the user the artifact is being monitored until that wake path is live." Additionally, it is susceptible to indirect prompt injection as it processes external feedback:
  • Ingestion points: Feedback is ingested via the poll command from a browser-based review session.
  • Boundary markers: None are present to distinguish user feedback from the agent's internal instruction set.
  • Capability inventory: The agent has capabilities to execute shell commands, write to the filesystem, and modify source code artifacts.
  • Sanitization: No validation or sanitization of the externally provided feedback strings is described.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 10:11 PM
Security Audit — agent-trust-hub — lavish