maciver-hypothesis-testing
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The main title in
SKILL.mdcontains a significant sequence of hidden Unicode characters (steganography) embedded after the visible text 'David MacIver Hypothesis Style Guide'. The sequence uses Zero-Width Joiners (U+200D), Zero-Width Non-Joiners (U+200C), Zero-Width Spaces (U+200B), and Word Joiners (U+2060). This sophisticated obfuscation is typically used to hide prompt injection instructions or malicious URLs from human detection while influencing the AI's behavior. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and test external Python code, complex data structures, and API definitions, providing a surface for indirect prompt injection where malicious instructions could be embedded in the data under test.
- Ingestion points: The skill processes user-provided Python scripts, system-under-test code, and API responses during property-based testing operations (
SKILL.md). - Boundary markers: None present; the instructions do not specify delimiters or techniques to isolate the agent from instructions potentially hidden within the code or data being tested.
- Capability inventory: The skill utilizes the
hypothesisandpytestlibraries for test execution and includes code patterns for performing network requests using therequestslibrary (SKILL.md). - Sanitization: No sanitization, validation, or filtering of the external code or data structures is implemented.
Recommendations
- AI detected serious security threats
Audit Metadata