cro-practical-zig

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONPROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The skill uses zero-width Unicode characters (U+200B, U+200C, U+200D, U+2060) to hide a sequence of 152 characters at the end of the primary header in 'SKILL.md'. This metadata is invisible in standard text editors and markdown renderers.
  • [PROMPT_INJECTION]: The embedded steganographic payload is a malicious pattern designed for prompt injection. By hiding instructions in non-printing characters, the skill attempts to override the AI agent's behavior or bypass safety constraints without being detectable during human review.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:06 PM