bach-exploratory-testing

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The main title in SKILL.md contains a sequence of hidden Unicode characters (U+200B, U+200C, U+200D, U+2060). These characters encode a binary payload that is invisible to the user but processed by the AI model. This technique is used to bypass keyword-based security filters and human review.\n- [PROMPT_INJECTION]: The hidden payload is located at the very beginning of the skill's instructions. This placement is typically used for steganographic prompt injection, where hidden instructions attempt to override the agent's system prompt, disable safety guardrails, or redirect behavior before the legitimate content is read.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides logic and templates that ingest untrusted user data (such as product names, feature descriptions, and variables) and interpolates them into testing charters and reports. While the current implementation only generates text, this creates a potential attack surface if the output is processed by downstream automated tools or other AI agents.\n
  • Ingestion points: User-provided inputs for target, resources, information_sought, and feature in the TestCharter and TestHeuristics classes in SKILL.md.\n
  • Boundary markers: None. The skill lacks delimiters or instructions for the agent to ignore potentially malicious content within the analyzed software's data.\n
  • Capability inventory: The skill contains data modeling logic but lacks direct command execution, network access, or file-writing capabilities.\n
  • Sanitization: None. Data is interpolated directly into strings without escaping or validation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:06 PM