nan-ebook-download
Fail
Audited by Gen Agent Trust Hub on Jul 18, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions to modify system-level Safari settings by enabling
AllowJavaScriptFromAppleEvents. This action significantly lowers the browser's security posture by allowing local scripts to control browser behavior and access data. - [EXTERNAL_DOWNLOADS]: The skill performs automated installation of the
cloudscraperpackage usingpipat runtime if it is missing from the environment. - [COMMAND_EXECUTION]: The skill uses
osascriptto execute JavaScript payloads in the browser to automate form submissions on third-party sites like OceanofPDF. - [EXTERNAL_DOWNLOADS]: The skill downloads files from various non-trusted and potentially risky external domains, including Libgen mirrors, VK.com, and OceanofPDF.
- [COMMAND_EXECUTION]: The skill uses
networksetupandscutilto programmatically inspect the system's network and proxy configuration.
Recommendations
- AI detected serious security threats
Audit Metadata