lipton-mutation-testing

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The title of the skill contains a large block of hidden Unicode characters (Zero-Width Space, Zero-Width Non-Joiner, and Zero-Width Joiner) that encode a hidden payload. This technique is used to hide information from human users while ensuring it is processed by the AI model context.
  • [PROMPT_INJECTION]: The hidden Unicode characters in the title represent a steganographic prompt injection attempt. This allows for the delivery of instructions that are not visible in the rendered documentation, potentially overriding agent behavior or bypassing safety filters.
  • [DYNAMIC_EXECUTION]: The code provided in the skill includes a MutationEngine class that uses the exec() function to execute dynamically generated Python code strings. This pattern allows for the execution of arbitrary code at runtime, which is inherently risky, especially if the input source code is provided by an untrusted source.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines functions that ingest arbitrary source code and execute it using exec(), creating a significant attack surface for indirect prompt injection.
  • Ingestion points: The run_mutation_testing method in SKILL.md accepts raw source_code as input from potentially untrusted sources.
  • Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in the implementation to separate user data from instructions.
  • Capability inventory: The skill uses exec() to run the code, providing a powerful execution environment with access to the python runtime.
  • Sanitization: There is no evidence of code sanitization, validation, or safety checks before the execution of the mutated strings.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:06 PM