skills/aeonfun/soul.md/soul/Gen Agent Trust Hub

soul

Fail

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: CRITICALPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The "SKILL.md" and several "QUICKSTART.md" files contain instructions to disregard the AI's standard identity and limitations. Phrases like "Never break character" and "No 'as an AI'" are used to ensure the persona stays consistent, effectively bypassing typical model self-identification guardrails.
  • [PROMPT_INJECTION]: The system is vulnerable to indirect prompt injection. It is designed to process large amounts of data fetched from external, attacker-influenceable sources like Twitter and public blog posts. There are no boundary markers or sanitization logic to prevent instructions within that data from being executed by the agent, particularly as the agent is told to "internalize fully" the content and "reason from worldview."
  • [COMMAND_EXECUTION]: The package includes several scripts (e.g., "scripts/fetch_yt.py", "scripts/fetch-data.sh") that use subprocess calls and shell commands to interact with the system and fetch external data. These are utility scripts intended for manual use by the developer to build the identity database.
  • [EXTERNAL_DOWNLOADS]: The identity building process involves downloading large corpuses of data from external domains including "twitter.com", "youtube.com", and "github.com". It also requires the installation of external Python dependencies such as "yt-dlp" and "youtube-transcript-api".
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 9, 2026, 05:11 PM
Security Audit — agent-trust-hub — soul