trump-perspective
Fail
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's reference documentation (
references/research/03-expression-dna.mdandreferences/research/06-timeline.md) contains links to external domains that have been flagged as malicious by automated scanners. Specifically, domains likeijels.comandblog.auspiciousassociates.comare associated with botnet and phishing activities. The filereferences/research/03-expression-dna.mdwas also identified as infected with anHttpRequest-infpayload. - [INDIRECT_PROMPT_INJECTION]: The skill implements an 'Agentic Protocol' that forces the agent to use external search tools (WebSearch) to verify facts before every response. This creates an extensive attack surface where the agent is instructed to ingest untrusted data from the internet. The inclusion of malicious URLs in the skill's own reference files suggests a deliberate attempt to lead the agent toward compromised sources during its 'fact-finding' phase.
- Ingestion points:
SKILL.md(Answer Workflow Step 2). - Boundary markers: While the skill includes 'Checkpoints' to verify poll data, it lacks delimiters or 'ignore-instructions' directives to protect the agent from instructions embedded in external search results.
- Capability inventory: The skill utilizes
WebSearchand provides complex roleplay instructions that prioritize persona consistency over safety filtering. - Sanitization: No sanitization or validation logic is present for data ingested through the
WebSearchtool. - [METADATA_POISONING]: The skill includes a 'Fidelity Scorecard' (
FIDELITY.md) that purports to grade the skill's safety and accuracy using academic citations (e.g., 'SkillLens', 'arXiv 2605.23899'). This metadata, along with simulated research logs, is designed to establish an authoritative veneer of safety that contradicts the actual presence of malicious payloads and risky architectural designs.
Recommendations
- CRITICAL: 1 infected file(s) detected - DO NOT USE
- CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 4 malicious URL(s) - DO NOT USE
Audit Metadata