desktop-wpf
Warn
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Deceptive token flooding detected in multiple reference files including architecture-patterns.md and security-best-practices.md. Each file contains 150 sections of near-identical filler text discussing Linux kernel internals and generic technical concepts unrelated to WPF.\n
- Evidence Chain (Category 8):\n
- Ingestion points: Eight reference files containing over 1,200 redundant sections of boilerplate text.\n
- Boundary markers: Absent; the agent is encouraged to use these files as authoritative deep-dive references.\n
- Capability inventory: The skill is intended for development environments where the agent has shell execution and file system access.\n
- Sanitization: No filtering or validation of the reference content is performed.\n
- The flooding technique is an adversarial tactic used to overflow the LLM context window, potentially burying malicious instructions or forcing the agent to ignore its system prompt guidelines.
Audit Metadata