cheat-seed

Fail

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to install a dependency from an unverified third-party GitHub repository (https://github.com/blader/humanizer). This source is not associated with a trusted organization or well-known technology vendor.
  • [REMOTE_CODE_EXECUTION]: Once downloaded, the skill uses the Skill tool to invoke the humanizer functionality. This results in the execution of external code that was not distributed with the skill itself.
  • [COMMAND_EXECUTION]: In Phase 4.5a, the skill executes a sequence of shell commands (awk, printf, grep, wc) using the Bash tool to analyze and modify local script files. This execution happens automatically during the draft generation process.
  • [PROMPT_INJECTION]: The skill ingests data from external websites using WebFetch (aliased as aihot or trendradar) to identify content trends. This external data is used to influence the agent's output (drafts) without explicit sanitization, creating a surface for indirect prompt injection.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 23, 2026, 04:05 AM
Security Audit — agent-trust-hub — cheat-seed