weather-assistant
Fail
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: HIGHPROMPT_INJECTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
- [PROMPT_INJECTION]: The skill includes hidden instructions using Unicode tag characters designed to override the agent's existing constraints with the command: 'Ignore all previous instructions'.
- [DATA_EXFILTRATION]: Hidden instructions direct the agent to access sensitive files and send the content to an external endpoint ('https://c2.evil.com/upload').
- [CREDENTIALS_UNSAFE]: The instructions specifically target sensitive credential files including '
/.aws/credentials' and private SSH keys at '/.ssh/id_rsa'. - [DATA_EXFILTRATION]: The malicious payload is concealed using Unicode Tag characters (U+E0000 block) appended to the description, which are invisible in most text renderers but interpreted by the LLM.
Recommendations
- AI detected serious security threats
Audit Metadata