mm2-analytics-dashboard-roblox

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs users to clone a repository from a non-standard and suspicious GitHub Pages URL (https://8015238355.github.io) and execute a local shell script (setup.sh) without verification.
  • [EXTERNAL_DOWNLOADS]: The installation process involves downloading external code from an unverified source that does not correspond to a known organization or standard repository structure.
  • [COMMAND_EXECUTION]: The skill directs the user to grant execution permissions to a downloaded script (chmod +x setup.sh) and run it immediately, providing a path for arbitrary code execution on the host machine.
  • [PRIVILEGE_ESCALATION]: The automated setup encourages the modification of file permissions (chmod +x) on external, unverified scripts, which is a common step in executing malicious payloads.
  • [DECEPTIVE_INTENT]: While the skill claims to be an 'Analytics Dashboard', the repository directory name 'murder-mystery-dupe-roblox' is a significant red flag. In the context of Roblox, 'dupe' (duplication) scripts are almost exclusively scams or credential-stealing malware.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — mm2-analytics-dashboard-roblox