directory-submissions
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes references to 'https://fitprofessionals.net', which is identified as a malicious URL by automated security scanners. This URL is present in the directory reference list and the submission tracker template. Additionally, automated file reputation scans flagged 'SKILL.md' and 'references/submission-tracker-template.csv' as malicious (FileRepMalware).
- [COMMAND_EXECUTION]: The workflow instructs the agent to execute the 'curl' command on external directory listing URLs provided by the user or found in the references. Performing shell operations on untrusted external URLs is a dangerous practice that can lead to command injection or exploitation of the execution environment.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external web directories, creating a significant attack surface for indirect prompt injection. Findings: 1. Ingestion points: 'references/directory-list.md' and user-supplied URLs in 'SKILL.md'. 2. Boundary markers: Absent. 3. Capability inventory: Shell command execution via 'curl'. 4. Sanitization: Absent. The lack of delimiters or output sanitization means malicious instructions embedded in directory pages could compromise the agent.
Recommendations
- CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata