mastra
Fail
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: HIGHDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The file
SKILL.mdconsists solely of a relative path../../../.config/agents/rules/mastra.md. This represents a directory traversal attempt to access files outside the skill's intended directory scope, specifically targeting configuration directories which may contain sensitive information. - [PROMPT_INJECTION]: By referencing external rule files via directory traversal, the skill may attempt to load instructions from unauthorized locations on the local filesystem, which could lead to the execution of unvalidated instructions and the override of the agent's safety constraints.
Recommendations
- AI detected serious security threats
Audit Metadata