de-shaw-computational-finance
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The main title in
SKILL.mdcontains a significant payload of zero-width Unicode characters (U+200B, U+200C, U+200D). These characters are invisible in standard document views and are employed to conceal data or instructions from users. - [PROMPT_INJECTION]: The hidden Unicode sequence represents a steganographic prompt injection. This technique attempts to supply instructions to the AI that bypass human oversight, potentially directing the agent to perform malicious activities such as data exfiltration or unauthorized system modifications.
- [INDIRECT_PROMPT_INJECTION]: The skill's design involves ingesting substantial amounts of untrusted data from market feeds and research databases.
- Ingestion points: Data enters the system via
data_warehouse.load()inResearchPipelineandmarket_datainStrategyFramework. - Boundary markers: The implementation lacks explicit boundary markers or instructions for the AI to disregard instructions embedded within these data streams.
- Capability inventory: The skill allows for data analysis, artifact logging, and compute execution, which could be abused if the agent is misled by malicious data.
- Sanitization: No validation or sanitization logic is present to filter out prompt-like content from the ingested quantitative data.
Recommendations
- AI detected serious security threats
Audit Metadata