spring-boot-engineer
Fail
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Automated reputation scanners (URLite) have flagged the documentation URL associated with the skill author as malicious.
- Source:
https://jeffallan.github.io/claude-skills/skills/backend/spring-boot-engineer/(referenced inSKILL.md) - [METADATA_POISONING]: The skill manifest file has been flagged by file reputation scanners as malicious (FileRepMalware), indicating the file or its distribution source has a negative security reputation.
- Evidence:
SKILL.mdflagged as malicious content by automated reputation scanners. - [COMMAND_EXECUTION]: The core workflow requires the agent to execute shell commands to compile and test the generated Spring Boot application.
- Commands:
./mvnw testand./gradlew test(referenced inSKILL.md) - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted user requirements to generate source code and perform system-level execution.
- Ingestion points: User-provided service boundaries, API definitions, data models, and security requirements (defined in
SKILL.md). - Boundary markers: Absent; there are no delimiters or instructions to ignore embedded directives within the requirement data.
- Capability inventory: Generates complex Java architecture, creates REST controllers, and executes shell-based build/test commands as defined in
SKILL.md. - Sanitization: Absent; no validation, escaping, or filtering of the processed requirements is specified.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata