jacobson-network-performance
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
- [OBFUSCATION]: The title of the skill in
SKILL.mdcontains an extensive block of zero-width characters (U+200B, U+200C, U+200D, and U+2060). These characters are invisible to human readers but accessible to the AI agent, serving as a covert channel for hiding data or instructions. - [PROMPT_INJECTION]: The use of Unicode steganography in the title is a high-risk indicator of hidden prompt injection. This technique is designed to embed instructions that bypass human review and security filters, potentially allowing an attacker to override the model's safety behavior.
- [PRIVILEGE_ESCALATION]: The Python implementation of
TracerouteinSKILL.mdusessocket.SOCK_RAWwithsocket.IPPROTO_ICMP. On most operating systems, creating raw sockets is restricted to administrative users. If an agent attempts to execute this code, it would likely require root/sudo access, posing a privilege escalation risk. - [COMMAND_EXECUTION]: The skill provides Python implementations for low-level network tools using
socketoperations. While functional for its stated purpose, these tools could be leveraged by a malicious agent to perform unauthorized network scanning or internal reconnaissance if provided with unintended targets.
Recommendations
- AI detected serious security threats
Audit Metadata