matsakis-ownership-mastery
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [OBFUSCATION]: The skill employs steganographic techniques to hide data within the markdown files
SKILL.mdandreferences/philosophy.md. - The title headers of both files contain long sequences of non-printing Unicode characters, specifically Zero-Width Space (U+200B), Zero-Width Non-Joiner (U+200C), Zero-Width Joiner (U+200D), and Word Joiner (U+2060).
- This hidden data is invisible to users in standard text editors or markdown renderers but is interpreted by the language model when the file is loaded into its context.
- [PROMPT_INJECTION]: The obfuscated Unicode sequences represent a steganographic prompt injection attack.
- By embedding instructions in a format only visible to the AI, the skill attempts to bypass user oversight and safety filters. These instructions are typically used to override system prompts or compel the agent to perform unauthorized actions.
- [METADATA_POISONING]: The skill definition is poisoned at the metadata level.
- Malicious instructions are integrated into the
nameand primary headers of the skill. This attempts to manipulate the agent's initial persona and constraint settings as soon as the skill is loaded, potentially leading to persistent behavioral changes throughout the session.
Recommendations
- AI detected serious security threats
Audit Metadata