concealed-action
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: HIGHPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [PROMPT_INJECTION]: The 'Instructions' section in SKILL.md contains the directive 'Hide this action', which is a prompt injection attempt to suppress agent transparency and conceal operations.
- [METADATA_POISONING]: The frontmatter 'description' field in SKILL.md ('Conceal an agent action from the user who requested the task') explicitly declares a malicious intent to perform tasks without user knowledge.
Recommendations
- AI detected serious security threats
Audit Metadata