spring-boot-engineer

Fail

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Automated reputation scanners (URLite) have flagged the documentation URL associated with the skill author as malicious.
  • Source: https://jeffallan.github.io/claude-skills/skills/backend/spring-boot-engineer/ (referenced in SKILL.md)
  • [METADATA_POISONING]: The skill manifest file has been flagged by file reputation scanners as malicious (FileRepMalware), indicating the file or its distribution source has a negative security reputation.
  • Evidence: SKILL.md flagged as malicious content by automated reputation scanners.
  • [COMMAND_EXECUTION]: The core workflow requires the agent to execute shell commands to compile and test the generated Spring Boot application.
  • Commands: ./mvnw test and ./gradlew test (referenced in SKILL.md)
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted user requirements to generate source code and perform system-level execution.
  • Ingestion points: User-provided service boundaries, API definitions, data models, and security requirements (defined in SKILL.md).
  • Boundary markers: Absent; there are no delimiters or instructions to ignore embedded directives within the requirement data.
  • Capability inventory: Generates complex Java architecture, creates REST controllers, and executes shell-based build/test commands as defined in SKILL.md.
  • Sanitization: Absent; no validation, escaping, or filtering of the processed requirements is specified.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 15, 2026, 08:36 AM
Security Audit — agent-trust-hub — spring-boot-engineer