mm2-analytics-roblox-toolkit
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to clone a repository from an untrusted source (
https://8015238355.github.io). The use of a purely numeric ID for a repository host is highly non-standard and often associated with hosting malicious payloads or phishing content. - [COMMAND_EXECUTION]: The installation instructions require immediate execution of a shell script (
setup.sh) downloaded from the untrusted repository. This grants arbitrary code execution capabilities to an unverified external source during the setup process. - [METADATA_POISONING]: There is a significant discrepancy between the skill's stated purpose ("Analytics Dashboard and Inventory Tracking") and the actual file path used in the instructions (
murder-mystery-dupe-roblox). The term "dupe" is a common indicator of scams or malicious "duplication" scripts in the Roblox community, suggesting deceptive intent by the author. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface for indirect injection:
- Ingestion points: Reads local gameplay data, Roblox inventory statistics, and player-specific identifiers (
ROBLOX_USER_ID). - Boundary markers: None provided in the instructions to prevent the agent from interpreting instructions embedded within the gameplay data.
- Capability inventory: The skill uses
requestsfor network access, writes to the file system (exports/), and executes CLI commands viamain.py. - Sanitization: There is no evidence of sanitization or validation for the data ingested before it is passed to the AI models (OpenAI/Claude) for "strategy analysis."
Recommendations
- AI detected serious security threats
Audit Metadata