aqr-factor-investing
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The primary header in
SKILL.md('AQR Capital Management Style Guide') contains a hidden payload consisting of over 150 non-printing Unicode characters, specifically zero-width spaces (U+200B), zero-width non-joiners (U+200C), zero-width joiners (U+200D), and word joiners (U+2060). This is a common method for concealing data or instructions within text that appears normal to human readers. - [PROMPT_INJECTION]: The use of hidden steganographic data in a critical instruction field is characteristic of an attempt to override agent behavior or inject commands that bypass human review. LLMs process these non-printing characters, meaning the agent receives potentially conflicting or malicious instructions that are invisible to the user, a high-risk security vector for bypassing safety guidelines.
Recommendations
- AI detected serious security threats
Audit Metadata