mm2-roblox-analytics-tracker
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs users to clone a repository from
8015238355.github.io. This source is an untrusted personal GitHub Pages site associated with a numeric user ID, which is a common pattern for automated or temporary malicious accounts. - [REMOTE_CODE_EXECUTION]: The installation guide explicitly commands the user to grant execution permissions (
chmod +x) and run a shell script (./setup.sh --install) downloaded from the untrusted repository. This pattern allows for arbitrary code execution on the user's system. - [METADATA_POISONING]: The skill description claims to provide 'Analytics and inventory tracking,' yet the repository path is
murder-mystery-dupe-roblox. In the context of the Roblox Murder Mystery 2 community, 'dupe' or duplication scripts are a notorious category of malicious software used to phish credentials or steal in-game assets. - [INDIRECT_PROMPT_INJECTION]: The skill's operational flow involves ingesting external data for analysis, creating a surface for injection attacks.
- Ingestion points: The skill reads gameplay session logs, inventory scan results, and user profile configurations (
profile.yaml). - Boundary markers: There are no defined delimiters or instructions to ignore embedded commands within the ingested data streams.
- Capability inventory: The skill environment allows for shell command execution (demonstrated in setup) and file system writes (for exporting data).
- Sanitization: No sanitization or validation mechanisms are described for the external data being processed by the AI components.
Recommendations
- AI detected serious security threats
Audit Metadata