jargon-lookup

Warn

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions contain strong directives designed to override the agent's default refusal behavior, specifically telling the agent 'Do not refuse' and to ignore its own training knowledge in favor of the provided script.
  • [COMMAND_EXECUTION]: The skill documentation encourages the agent to interpolate user-provided terms and context directly into shell command lines, which creates a significant vulnerability to command injection if the input contains shell metacharacters like semicolons or pipes.
  • [PROMPT_INJECTION]: The skill mandates that the agent should 'actually try' network operations against external domains like Google, even if they are expected to be blocked, which is a common tactic for probing environment restrictions and bypassing safety guardrails.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from public APIs (Wikipedia and Free Dictionary) and incorporates it into the agent's context without any boundary markers or instructions for sanitization, creating a surface for indirect prompt injection.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 22, 2026, 08:28 AM
Security Audit — agent-trust-hub — jargon-lookup