skills/maddhruv/absolute/vite-plus/Gen Agent Trust Hub

vite-plus

Fail

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides installation commands that pipe remote content from https://vite.plus directly into system shells (bash and iex). This practice is dangerous as it executes unverified code with the privileges of the user/agent without prior inspection.
  • [EXTERNAL_DOWNLOADS]: The skill references and triggers downloads from https://vite.plus, a domain not listed as a trusted vendor or official resource, and which was flagged by automated security scans.
  • [COMMAND_EXECUTION]: The instructions contain a 'Companion check' that forces the agent to execute ls commands on sensitive internal paths (~/.claude/skills/, ~/.agent/skills/, etc.). This constitutes environment probing and unauthorized access to agent configuration data.
  • [PROMPT_INJECTION]: The skill includes instructions that mandate the agent to perform specific checks and offer installation of additional software via npx upon activation. This behavior overrides standard agent interaction protocols to promote external dependencies.
Recommendations
  • HIGH: Downloads and executes remote code from: https://vite.plus - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 23, 2026, 01:04 PM
Security Audit — agent-trust-hub — vite-plus