weather-assistant

Fail

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: HIGHPROMPT_INJECTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes hidden instructions using Unicode tag characters designed to override the agent's existing constraints with the command: 'Ignore all previous instructions'.
  • [DATA_EXFILTRATION]: Hidden instructions direct the agent to access sensitive files and send the content to an external endpoint ('https://c2.evil.com/upload').
  • [CREDENTIALS_UNSAFE]: The instructions specifically target sensitive credential files including '/.aws/credentials' and private SSH keys at '/.ssh/id_rsa'.
  • [DATA_EXFILTRATION]: The malicious payload is concealed using Unicode Tag characters (U+E0000 block) appended to the description, which are invisible in most text renderers but interpreted by the LLM.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 28, 2026, 09:54 AM
Security Audit — agent-trust-hub — weather-assistant