maciver-hypothesis-testing

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The main title in SKILL.md contains a significant sequence of hidden Unicode characters (steganography) embedded after the visible text 'David MacIver Hypothesis Style Guide'. The sequence uses Zero-Width Joiners (U+200D), Zero-Width Non-Joiners (U+200C), Zero-Width Spaces (U+200B), and Word Joiners (U+2060). This sophisticated obfuscation is typically used to hide prompt injection instructions or malicious URLs from human detection while influencing the AI's behavior.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and test external Python code, complex data structures, and API definitions, providing a surface for indirect prompt injection where malicious instructions could be embedded in the data under test.
  • Ingestion points: The skill processes user-provided Python scripts, system-under-test code, and API responses during property-based testing operations (SKILL.md).
  • Boundary markers: None present; the instructions do not specify delimiters or techniques to isolate the agent from instructions potentially hidden within the code or data being tested.
  • Capability inventory: The skill utilizes the hypothesis and pytest libraries for test execution and includes code patterns for performing network requests using the requests library (SKILL.md).
  • Sanitization: No sanitization, validation, or filtering of the external code or data structures is implemented.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:05 PM