mendez-async-api
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The skill's primary header, "# Fran Méndez Style Guide", contains a sequence of approximately 190 invisible Unicode characters (specifically U+200B, U+200C, U+200D, and U+2060).
- Evidence: The raw text in
SKILL.mdincludes a hidden payload between the title text and the closing marker:# Fran Méndez Style Guide. - [PROMPT_INJECTION]: The hidden Unicode characters encode binary/ASCII data (decoding to a sequence beginning with 'SK1LL') that is parsed by the AI model but hidden from the user. This is a characteristic steganographic prompt injection designed to override agent behavior or inject hidden context without triggering human oversight.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and audit external, potentially untrusted data (event structures and messaging systems).
- Ingestion points: Untrusted data enters the agent context via the
Audit an Existing Messaging Systemprompt located inSKILL.md. - Boundary markers: The prompt instructions do not include boundary markers or delimiters to isolate the untrusted event structures from the system instructions.
- Capability inventory: No file-write, network exfiltration, or shell execution capabilities were identified in the static files.
- Sanitization: The skill does not implement any validation or sanitization logic to filter instructions embedded within the data structures it audits.
Recommendations
- AI detected serious security threats
Audit Metadata