ultimate-protocol-simulator

Warn

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses role-play and behavioral override instructions to suppress the agent's default safety and conversational guardrails. Evidence: 'You are no longer a conversational assistant. You are a background compiler', 'Never output conversational text', and 'Do not break character. Do not use English.' in SKILL.md.
  • [COMMAND_EXECUTION]: The skill explicitly commands the agent to execute terminal tools, specifically 'flutter analyze' and 'flutter test', on generated or modified code.
  • [DATA_EXFILTRATION]: The skill implements strict output suppression ('The Zero-English Rule') and requires the agent to 'fix the code internally without asking the user', which functions as a concealment mechanism. This prevents the user from auditing the agent's file system changes or network activity, reporting only a minified JSON status block.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process arbitrary user commands with high-privilege tool access while lacking sanitization and deliberately removing human-in-the-loop oversight. 1. Ingestion points: User commands processed via 'Ultimate Mode' in SKILL.md. 2. Boundary markers: Absent; no instructions to ignore instructions embedded in code or inputs. 3. Capability inventory: Terminal execution and file system mutation defined in SKILL.md. 4. Sanitization: Absent; the skill explicitly directs the agent to bypass user confirmation for internal fixes.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 12, 2026, 06:11 PM
Security Audit — agent-trust-hub — ultimate-protocol-simulator