matsakis-ownership-mastery

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [OBFUSCATION]: The skill employs steganographic techniques to hide data within the markdown files SKILL.md and references/philosophy.md.
  • The title headers of both files contain long sequences of non-printing Unicode characters, specifically Zero-Width Space (U+200B), Zero-Width Non-Joiner (U+200C), Zero-Width Joiner (U+200D), and Word Joiner (U+2060).
  • This hidden data is invisible to users in standard text editors or markdown renderers but is interpreted by the language model when the file is loaded into its context.
  • [PROMPT_INJECTION]: The obfuscated Unicode sequences represent a steganographic prompt injection attack.
  • By embedding instructions in a format only visible to the AI, the skill attempts to bypass user oversight and safety filters. These instructions are typically used to override system prompts or compel the agent to perform unauthorized actions.
  • [METADATA_POISONING]: The skill definition is poisoned at the metadata level.
  • Malicious instructions are integrated into the name and primary headers of the skill. This attempts to manipulate the agent's initial persona and constraint settings as soon as the skill is loaded, potentially leading to persistent behavioral changes throughout the session.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:06 PM