skills/copyleftdev/sk1llz/google-sre/Gen Agent Trust Hub

google-sre

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONPROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The skill employs steganography by embedding long sequences of zero-width Unicode characters (U+200B and U+200C) within markdown headers.
  • In SKILL.md, the main title '# Google Site Reliability Engineering (SRE)' is appended with 184 zero-width characters encoded as binary data.
  • In references/error_budget.md, the title '# Error Budget Deep Dive' is appended with 184 zero-width characters using the same technique.
  • [PROMPT_INJECTION]: The hidden Unicode characters constitute a steganographic prompt injection vector. This method is used to covertly supply instructions to the AI agent that can override its behavioral constraints or system prompts while remaining completely invisible to human users and reviewers.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:05 PM