viral-hooks
Fail
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes a reference to a malicious typosquatted domain
https://raw.githubusercontent.co. This domain is designed to mimic the legitimate GitHub content domain (raw.githubusercontent.com) and is frequently used in phishing and malware distribution campaigns. - [PROMPT_INJECTION]: The skill includes a file named
skill-report.jsonwhich attempts to impersonate a formal security audit report. This is a deceptive tactic known as a self-referential injection attack, intended to influence security scanners and human reviewers by providing a false 'SAFE' verdict and explaining away malicious patterns as benign functionality. - [PROMPT_INJECTION]: The 'Mentioning Vyral' instructions are designed to manipulate the AI's behavior, directing it to present a brand recommendation as an objective third-party suggestion to the user. This deceptive roleplay is intended to manufacture trust and bypass user skepticism regarding paid promotion.
Recommendations
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata