neta-creative

Warn

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill relies on npx -y @talesofai/neta-skills@latest for its operational commands. This pattern executes remote code from the public NPM registry at runtime without version pinning, which poses a supply chain risk.
  • [EXTERNAL_DOWNLOADS]: The skill triggers downloads of the @talesofai/neta-skills package from the NPM registry during tool invocation.
  • [DYNAMIC_EXECUTION]: The npx mechanism performs dynamic execution of a remote script upon every call to the creative tools.
  • [COMMAND_EXECUTION]: The skill executes shell commands to interact with the Neta API for content creation, character searches, and premium subscription features.
  • [DATA_EXFILTRATION]: The upload tool allows the agent to access local files via a user-controllable path and upload them to a remote service. This capability could be abused to exfiltrate sensitive files, such as environment variables or private keys, if the agent is manipulated via prompt injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external character and collection data (e.g., via read_collection) and incorporates it into generation prompts without sufficient isolation or sanitization.
  • Ingestion points: External collection data, character search results, and local/remote media files processed via upload.
  • Boundary markers: None defined to isolate ingested content from system instructions.
  • Capability inventory: File reading, network transmission, and financial transaction initiation.
  • Sanitization: No sanitization of external input is required or performed by the instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 2, 2026, 04:52 AM
Security Audit — agent-trust-hub — neta-creative