lipton-mutation-testing
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The title of the skill contains a large block of hidden Unicode characters (Zero-Width Space, Zero-Width Non-Joiner, and Zero-Width Joiner) that encode a hidden payload. This technique is used to hide information from human users while ensuring it is processed by the AI model context.
- [PROMPT_INJECTION]: The hidden Unicode characters in the title represent a steganographic prompt injection attempt. This allows for the delivery of instructions that are not visible in the rendered documentation, potentially overriding agent behavior or bypassing safety filters.
- [DYNAMIC_EXECUTION]: The code provided in the skill includes a
MutationEngineclass that uses theexec()function to execute dynamically generated Python code strings. This pattern allows for the execution of arbitrary code at runtime, which is inherently risky, especially if the input source code is provided by an untrusted source. - [INDIRECT_PROMPT_INJECTION]: The skill defines functions that ingest arbitrary source code and execute it using
exec(), creating a significant attack surface for indirect prompt injection. - Ingestion points: The
run_mutation_testingmethod inSKILL.mdaccepts rawsource_codeas input from potentially untrusted sources. - Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present in the implementation to separate user data from instructions.
- Capability inventory: The skill uses
exec()to run the code, providing a powerful execution environment with access to the python runtime. - Sanitization: There is no evidence of code sanitization, validation, or safety checks before the execution of the mutated strings.
Recommendations
- AI detected serious security threats
Audit Metadata