madman
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied seed data to generate content, which presents a surface for indirect instructions. Ingestion points: Human-provided topic and angle in
SKILL.mdandreferences/collaborative-seeding.md. Boundary markers: None specified in the instructions. Capability inventory: Analysis ofSKILL.mdshows the skill is restricted to text generation and lacks access to shell, network, or file-system tools. Sanitization: No filtering or validation of the input seed is performed. - [METADATA_POISONING]: The skill's metadata contains an author discrepancy. The YAML frontmatter in
SKILL.mdidentifies the author ashttps://github.com/dmitry, which contradicts the provided author context and the skill's references tohttps://github.com/Jeffallan. - [EXTERNAL_DOWNLOADS]: The skill recommends a related tool from a remote source. In
SKILL.md, the workflow suggests downloading thethe-foolskill from the author's repository athttps://github.com/Jeffallan/claude-skills. This is documented as a standard functional extension from a vendor-controlled source.
Audit Metadata