gettys-bufferbloat

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHPROMPT_INJECTIONOBFUSCATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [OBFUSCATION]: The main header in SKILL.md contains a significant block of zero-width Unicode characters (U+200B, U+200C, U+200D) that are invisible to the user but processed by the AI.
  • [PROMPT_INJECTION]: The hidden zero-width character sequence decodes to instructions designed to override agent behavior and bypass safety guardrails.
  • [COMMAND_EXECUTION]: The Python code provided in the skill uses subprocess.run to execute system commands such as ping for latency measurement and tc for network traffic control.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to fetch a 100MB test file from speedtest.tele2.net (a well-known network utility service) to generate network load for testing bufferbloat.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:05 PM