report-writing
Fail
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill recommends and provides commands to install an external agent skill by cloning the repository
https://github.com/blader/humanizer.git. Since skills define agent logic and can include scripts, this introduces a mechanism for running unvetted code from a third-party source.\n- [EXTERNAL_DOWNLOADS]: Includes instructions for the agent to download content viagit clonefrom an external, untrusted source (GitHub user 'blader').\n- [COMMAND_EXECUTION]: Provides instructions for the agent to execute shell commands, including cloning external repositories and querying the GitHub API for repository security information.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data. Evidence Chain: 1. Ingestion points:findings.md,verdict.md,poc_*(inSKILL.md); 2. Boundary markers: Absent; 3. Capability inventory:git clone,gh api,curl, and file writing; 4. Sanitization: Absent.
Recommendations
- AI detected serious security threats
Audit Metadata