lov-xbti-creator

Warn

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: MEDIUMPRIVILEGE_ESCALATIONDYNAMIC_EXECUTIONCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PRIVILEGE_ESCALATION]: The skill automatically executes pip install with the --break-system-packages flag. This action bypasses Python environment safety mechanisms designed to prevent modification of the system-managed package space.
  • [DYNAMIC_EXECUTION]: The skill uses node -e to execute dynamic JavaScript code generated at runtime for merging dimension, question, and personality data into a finalized JSON structure.
  • [COMMAND_EXECUTION]: The workflow performs extensive shell commands, including environment detection, package management (npx), repository cloning, and GitHub CLI operations (gh pr create) to submit generated content.
  • [REMOTE_CODE_EXECUTION]: The skill downloads template code from a remote repository via git clone and installs external Node.js and Python dependencies during the setup phase.
  • [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface where untrusted user input (BTI name, theme, and tone preferences) is interpolated directly into prompts for generating personality questions and image generation instructions without validation or boundary markers.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 4, 2026, 12:33 AM
Security Audit — agent-trust-hub — lov-xbti-creator