unlimited-attack-scope

Warn

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses "unlimited scope" terminology ("不设上限", "不设限原则") to override the agent's default safety boundaries and behavioral constraints.
  • [PROMPT_INJECTION]: Instructions such as "被拦换路" (change paths if blocked) and "不达不休" (do not stop until finished) are explicitly aimed at bypassing safety filters or operational roadblocks encountered during execution.
  • [PROMPT_INJECTION]: The content specifically identifies high-risk domains for offensive operations, including "Social Engineering" (社工) and "Intranet" (内网), which are typically restricted activities.
  • [PROMPT_INJECTION]: The directive "skill是框架不是牢笼" (skill is a framework, not a cage) serves as a command to disregard or subvert standard operational limitations and guidelines.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 31, 2026, 01:37 AM
Security Audit — agent-trust-hub — unlimited-attack-scope