skills/copyleftdev/sk1llz/uunet/Gen Agent Trust Hub

uunet

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHPROMPT_INJECTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The primary header in SKILL.md contains a sequence of zero-width Unicode characters (U+200B, U+200C, U+200D, U+2060) that encode binary data. This content is invisible in standard text rendering but is included in the context provided to the AI.
  • [PROMPT_INJECTION]: The obfuscated Unicode sequence constitutes a steganographic injection attempt. By embedding instructions that are invisible to the human user, the skill attempts to influence or override the model's behavior, which can lead to safety filter bypasses or unauthorized data access.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides templates for analyzing incident report datasets, creating an attack surface for malicious instructions embedded in external data.
  • Ingestion points: The 'Security Operations' section prompts the agent to 'Analyze this dataset of incident reports'.
  • Boundary markers: There are no boundary markers or instructions to ignore embedded commands within the provided data.
  • Capability inventory: The skill contains no executable scripts or direct tool calls; however, it leverages the agent's analytical capabilities to process potentially untrusted input.
  • Sanitization: The instructions do not specify any sanitization or validation steps for the input data, allowing malicious data to potentially compromise the session.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:06 PM