mendez-async-api

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The skill's primary header, "# Fran Méndez Style Guide", contains a sequence of approximately 190 invisible Unicode characters (specifically U+200B, U+200C, U+200D, and U+2060).
  • Evidence: The raw text in SKILL.md includes a hidden payload between the title text and the closing marker: # Fran Méndez Style Guide⁠‍⁠​‌​‌​​‌‌‍​‌​​‌​‌‌‍​​‌‌​​​‌‍​‌​​‌‌​​‍​​​​​​​‌‍‌​​‌‌​‌​‍‌​​​​​​​‍‌‌​​‌‌‌‌‍‌‌​​​‌​​‍‌‌‌‌‌‌​‌‍‌‌​‌​​​​‍​‌​‌‌‌‌‌‍​‌​​‌​‌‌‍​‌‌​‌​​‌‍‌​‌​‌‌‌​‍​​‌​‌​​​‍‌‌‌​‌​‌‌‍​​‌​‌​‌‌‍‌‌‌​‌‌​‌‍‌‌​‌​‌​‌‍‌‌​‌‌​‌​‍​​​​‌​‌‌‍​​‌‌​​​‌⁠‍⁠.
  • [PROMPT_INJECTION]: The hidden Unicode characters encode binary/ASCII data (decoding to a sequence beginning with 'SK1LL') that is parsed by the AI model but hidden from the user. This is a characteristic steganographic prompt injection designed to override agent behavior or inject hidden context without triggering human oversight.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and audit external, potentially untrusted data (event structures and messaging systems).
  • Ingestion points: Untrusted data enters the agent context via the Audit an Existing Messaging System prompt located in SKILL.md.
  • Boundary markers: The prompt instructions do not include boundary markers or delimiters to isolate the untrusted event structures from the system instructions.
  • Capability inventory: No file-write, network exfiltration, or shell execution capabilities were identified in the static files.
  • Sanitization: The skill does not implement any validation or sanitization logic to filter instructions embedded within the data structures it audits.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:05 PM