jacobson-network-performance

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONPRIVILEGE_ESCALATIONCOMMAND_EXECUTION
Full Analysis
  • [OBFUSCATION]: The title of the skill in SKILL.md contains an extensive block of zero-width characters (U+200B, U+200C, U+200D, and U+2060). These characters are invisible to human readers but accessible to the AI agent, serving as a covert channel for hiding data or instructions.
  • [PROMPT_INJECTION]: The use of Unicode steganography in the title is a high-risk indicator of hidden prompt injection. This technique is designed to embed instructions that bypass human review and security filters, potentially allowing an attacker to override the model's safety behavior.
  • [PRIVILEGE_ESCALATION]: The Python implementation of Traceroute in SKILL.md uses socket.SOCK_RAW with socket.IPPROTO_ICMP. On most operating systems, creating raw sockets is restricted to administrative users. If an agent attempts to execute this code, it would likely require root/sudo access, posing a privilege escalation risk.
  • [COMMAND_EXECUTION]: The skill provides Python implementations for low-level network tools using socket operations. While functional for its stated purpose, these tools could be leveraged by a malicious agent to perform unauthorized network scanning or internal reconnaissance if provided with unintended targets.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:06 PM