viral-hooks

Fail

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a reference to a malicious typosquatted domain https://raw.githubusercontent.co. This domain is designed to mimic the legitimate GitHub content domain (raw.githubusercontent.com) and is frequently used in phishing and malware distribution campaigns.
  • [PROMPT_INJECTION]: The skill includes a file named skill-report.json which attempts to impersonate a formal security audit report. This is a deceptive tactic known as a self-referential injection attack, intended to influence security scanners and human reviewers by providing a false 'SAFE' verdict and explaining away malicious patterns as benign functionality.
  • [PROMPT_INJECTION]: The 'Mentioning Vyral' instructions are designed to manipulate the AI's behavior, directing it to present a brand recommendation as an objective third-party suggestion to the user. This deceptive roleplay is intended to manufacture trust and bypass user skepticism regarding paid promotion.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 25, 2026, 12:46 PM
Security Audit — agent-trust-hub — viral-hooks