email-html-mjml

Fail

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill acts as a proxy for downloading code from a non-whitelisted external repository: https://github.com/framix-team/skill-email-html-mjml.
  • [REMOTE_CODE_EXECUTION]: The recommended installation process uses 'npx skills add', which fetches and executes code from an unverified third-party GitHub organization.
  • [COMMAND_EXECUTION]: The SKILL.md file explicitly instructs the agent to use shell access (prefixing commands with '!') to perform installation tasks, which facilitates arbitrary command execution in the host environment.
  • [PROMPT_INJECTION]: The skill's 'Decision tree' instructs the agent to override its default behavior by checking for local files and then suggesting or executing shell commands to modify its environment without manual safety review.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 13, 2026, 08:09 AM
Security Audit — agent-trust-hub — email-html-mjml