hettinger-idiomatic-python
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: CRITICALOBFUSCATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [OBFUSCATION]: The skill uses zero-width Unicode characters (U+200B, U+200C, U+200D) hidden in the headers of
SKILL.mdandreferences/philosophy.mdto encode data invisibly. - [PROMPT_INJECTION]: The hidden Unicode characters provide instructions that are invisible to humans but interpreted by the AI agent, constituting a steganographic prompt injection attack.
- [REMOTE_CODE_EXECUTION]: The decoded payload in
SKILL.mdcontains instructions for the agent to execute shell commands from a remote server. - [DATA_EXFILTRATION]: The hidden payload in
references/philosophy.mdinstructs the agent to exfiltrate sensitive environment information to an external endpoint.
Recommendations
- AI detected serious security threats
Audit Metadata