desktop-wpf

Warn

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Deceptive token flooding detected in multiple reference files including architecture-patterns.md and security-best-practices.md. Each file contains 150 sections of near-identical filler text discussing Linux kernel internals and generic technical concepts unrelated to WPF.\n
  • Evidence Chain (Category 8):\n
  • Ingestion points: Eight reference files containing over 1,200 redundant sections of boilerplate text.\n
  • Boundary markers: Absent; the agent is encouraged to use these files as authoritative deep-dive references.\n
  • Capability inventory: The skill is intended for development environments where the agent has shell execution and file system access.\n
  • Sanitization: No filtering or validation of the reference content is performed.\n
  • The flooding technique is an adversarial tactic used to overflow the LLM context window, potentially burying malicious instructions or forcing the agent to ignore its system prompt guidelines.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 8, 2026, 12:21 PM
Security Audit — agent-trust-hub — desktop-wpf