directory-submissions

Fail

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The resource file 'references/submission-tracker-template.csv' includes a link to 'https://fitprofessionals.net', which is flagged by automated scanners as a blacklisted domain.
  • [DATA_EXFILTRATION]: The skill guides the agent and user to share product metadata and founder information with a wide range of external directories, creating a significant surface for data exposure to third parties.
  • [PROMPT_INJECTION]: The skill instructions in 'SKILL.md' direct the agent to read external context from files such as '.agents/product-marketing.md'. This ingestion of untrusted data creates a surface for indirect prompt injection, as the skill does not define boundary markers or sanitization for this content.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 27, 2026, 12:30 AM
Security Audit — agent-trust-hub — directory-submissions