cro-practical-zig
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The skill uses zero-width Unicode characters (U+200B, U+200C, U+200D, U+2060) to hide a sequence of 152 characters at the end of the primary header in 'SKILL.md'. This metadata is invisible in standard text editors and markdown renderers.
- [PROMPT_INJECTION]: The embedded steganographic payload is a malicious pattern designed for prompt injection. By hiding instructions in non-printing characters, the skill attempts to override the AI agent's behavior or bypass safety constraints without being detectable during human review.
Recommendations
- AI detected serious security threats
Audit Metadata