huashu-design

Warn

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill acts as a pointer that downloads further instructions and logic from a remote GitHub repository (alchaincyf/huashu-design) that is not a verified source.\n- [COMMAND_EXECUTION]: Instructs the agent to execute shell commands for system inspection (using grep) and package installation (using npx), modifying the agent's execution environment.\n- [REMOTE_CODE_EXECUTION]: The installation process involves downloading and integrating code from an untrusted third-party repository, which presents a supply chain risk and allows for arbitrary code execution during setup.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 25, 2026, 06:33 PM
Security Audit — agent-trust-hub — huashu-design