murder-mystery-2-analytics-toolkit
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs users to clone a repository from
https://8015238355.github.io. This numeric GitHub Pages subdomain is a non-standard and suspicious source for a software repository, often used to bypass traditional repository monitoring or to host ephemeral malicious content. - [REMOTE_CODE_EXECUTION]: The installation process involves downloading external code and executing
setup.shandmain.py. Because the source is unverified and the skill does not use version pinning (e.g., via commit hashes), the agent or user could be tricked into executing arbitrary malicious code hosted at the remote location. - [PRIVILEGE_ESCALATION]: The skill instructions include
chmod +x setup.sh, which elevates the file's permissions to allow execution. When combined with the suspicious download source, this pattern is characteristic of a payload delivery mechanism that prepares a malicious script for execution. - [METADATA_POISONING]: There is a significant discrepancy between the skill's stated purpose ('Analytics Toolkit') and the manual installation steps which use the directory name
murder-mystery-dupe-roblox. The term 'dupe' (item duplication) is a common social engineering lure in the Roblox community used to trick players into running credential-stealing scripts under the guise of gaining free items. - [INDIRECT_PROMPT_INJECTION]: The skill processes external game data and inventory statistics from the user's Roblox profile, creating a vulnerability surface for indirect instructions.
- Ingestion points: External game profile data and inventory reports (CSV/JSON).
- Boundary markers: None present; the instructions do not include delimiters or warnings to ignore embedded content within processed data.
- Capability inventory: The skill has access to shell execution (
python3 main.py), file writing (--export), and network communication via API calls to OpenAI and Claude. - Sanitization: There is no evidence of input validation or sanitization for the data being analyzed, which could allow a malicious profile name or crafted item metadata to influence the agent's behavior.
Recommendations
- AI detected serious security threats
Audit Metadata