mitre-attack-framework
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: The headers in
SKILL.mdandreferences/techniques.mdcontain hidden zero-width Unicode characters (U+200B, U+200C, U+200D). This steganographic technique is used to conceal content from human users while presenting it to the AI agent during context loading. - [PROMPT_INJECTION]: The hidden content in the skill's headers constitutes a stealthy prompt injection. This is an adversarial pattern intended to secretly influence agent behavior or bypass safety protocols without appearing in the readable text.
- [INDIRECT_PROMPT_INJECTION]: The
scripts/coverage_analyzer.pyscript parses external YAML-based Sigma rules and extracts rule titles for reporting. Because the extracted text is not sanitized, malicious instructions within a rule file could be used to perform an indirect prompt injection attack when the agent reviews the analysis results. Ingestion points: Rule parsing inscripts/coverage_analyzer.py(titles from.ymland.yamlfiles). Boundary markers: None. Metadata is directly interpolated into report strings. Capability inventory: The skill environment typically includes file system, network, and command execution tools. Sanitization: None. The script does not escape or validate metadata extracted from rule files.
Recommendations
- AI detected serious security threats
Audit Metadata