gettys-bufferbloat
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHPROMPT_INJECTIONOBFUSCATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [OBFUSCATION]: The main header in
SKILL.mdcontains a significant block of zero-width Unicode characters (U+200B, U+200C, U+200D) that are invisible to the user but processed by the AI. - [PROMPT_INJECTION]: The hidden zero-width character sequence decodes to instructions designed to override agent behavior and bypass safety guardrails.
- [COMMAND_EXECUTION]: The Python code provided in the skill uses
subprocess.runto execute system commands such aspingfor latency measurement andtcfor network traffic control. - [EXTERNAL_DOWNLOADS]: The skill uses
curlto fetch a 100MB test file fromspeedtest.tele2.net(a well-known network utility service) to generate network load for testing bufferbloat.
Recommendations
- AI detected serious security threats
Audit Metadata