neta-creative
Warn
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill relies on
npx -y @talesofai/neta-skills@latestfor its operational commands. This pattern executes remote code from the public NPM registry at runtime without version pinning, which poses a supply chain risk. - [EXTERNAL_DOWNLOADS]: The skill triggers downloads of the
@talesofai/neta-skillspackage from the NPM registry during tool invocation. - [DYNAMIC_EXECUTION]: The
npxmechanism performs dynamic execution of a remote script upon every call to the creative tools. - [COMMAND_EXECUTION]: The skill executes shell commands to interact with the Neta API for content creation, character searches, and premium subscription features.
- [DATA_EXFILTRATION]: The
uploadtool allows the agent to access local files via a user-controllable path and upload them to a remote service. This capability could be abused to exfiltrate sensitive files, such as environment variables or private keys, if the agent is manipulated via prompt injection. - [INDIRECT_PROMPT_INJECTION]: The skill processes external character and collection data (e.g., via
read_collection) and incorporates it into generation prompts without sufficient isolation or sanitization. - Ingestion points: External collection data, character search results, and local/remote media files processed via
upload. - Boundary markers: None defined to isolate ingested content from system instructions.
- Capability inventory: File reading, network transmission, and financial transaction initiation.
- Sanitization: No sanitization of external input is required or performed by the instructions.
Audit Metadata