thompson-elegant-systems
Fail
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [OBFUSCATION]: The skill utilizes zero-width Unicode characters (U+200B Zero-Width Space, U+200C Zero-Width Non-Joiner, and U+200D Zero-Width Joiner) to embed binary-encoded data within the markdown headers of
SKILL.mdandreferences/philosophy.md. The hidden data is delimited by U+2060 (Word Joiner) characters. Binary decoding of the hidden content inSKILL.mdreveals a structured byte sequence starting with 'SK1L', confirming the presence of intentionally concealed data. - [PROMPT_INJECTION]: The presence of hidden steganographic instructions in the skill's primary documentation is a high-risk indicator of prompt injection. This technique allows a malicious author to deliver instructions to the AI agent that are hidden from the human user's view, potentially directing the agent to ignore its safety guidelines or perform unauthorized actions.
- [METADATA_POISONING]: The skill embeds malicious instructions within the primary title metadata of the markdown files. While the visible metadata fields (name, description) appear benign, the hidden content in the headers acts as a deceptive metadata layer designed to influence the agent's behavior at the moment the skill is loaded into context.
Recommendations
- AI detected serious security threats
Audit Metadata