fullstack-guardian
Fail
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill contains a documentation reference to
jeffallan.github.io/claude-skills/skills/security/fullstack-guardian/, which has been blacklisted and flagged as malicious by automated scanners.\n- [REMOTE_CODE_EXECUTION]: The main skill configuration fileSKILL.mdis flagged by file reputation scanners as potential malware. This represents a critical risk because the skill provides templates and instructions for the agent to generate and execute CI/CD pipelines, Docker configurations, and server-side logic which could be weaponized.\n- [METADATA_POISONING]: The skill's internal metadata attributes authorship to 'Jeffallan', which contradicts the system-provided author context of 'emmraan'. This inconsistency indicates potential impersonation or unauthorized use of the content to mask malicious modifications.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to take arbitrary user requirements and transform them into technical designs and code implementations. It lacks specific instruction boundary markers or data sanitization mechanisms, making it a viable target for indirect prompt injection attacks that could result in the generation of insecure or malicious application code.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata