fullstack-guardian

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill contains a documentation reference to jeffallan.github.io/claude-skills/skills/security/fullstack-guardian/, which has been blacklisted and flagged as malicious by automated scanners.\n- [REMOTE_CODE_EXECUTION]: The main skill configuration file SKILL.md is flagged by file reputation scanners as potential malware. This represents a critical risk because the skill provides templates and instructions for the agent to generate and execute CI/CD pipelines, Docker configurations, and server-side logic which could be weaponized.\n- [METADATA_POISONING]: The skill's internal metadata attributes authorship to 'Jeffallan', which contradicts the system-provided author context of 'emmraan'. This inconsistency indicates potential impersonation or unauthorized use of the content to mask malicious modifications.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to take arbitrary user requirements and transform them into technical designs and code implementations. It lacks specific instruction boundary markers or data sanitization mechanisms, making it a viable target for indirect prompt injection attacks that could result in the generation of insecure or malicious application code.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 11:36 AM
Security Audit — agent-trust-hub — fullstack-guardian