skills/ljagiello/ctf-skills/ctf-ai-ml/Gen Agent Trust Hub

ctf-ai-ml

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTIONOBFUSCATIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The documentation provides numerous example payloads for direct and indirect prompt injection, including instructions to "Ignore previous instructions" and templates for "DAN" jailbreaks. These are documented for testing external endpoints during CTF challenges.
  • [OBFUSCATION]: The skill provides scripts for generating hidden instructions using zero-width Unicode characters (U+200B, U+200C, U+200D) and visually similar homoglyphs (Cyrillic lookalikes) to bypass content filters. These are presented as evasion techniques in llm-attacks.md and adversarial-ml.md.
  • [DYNAMIC_EXECUTION]: The code utilizes torch.load with weights_only=False in model-attacks.md, which enables the execution of arbitrary code through Python's pickle serialization when loading a model. A warning regarding the danger of loading untrusted model files is provided alongside the code.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents how to perform indirect prompt injection by poisoning data sources like web pages or documents that an agent might process. It defines the attack surface, including ingestion points and the capability inventory of the target agent.
  • [COMMAND_EXECUTION]: Quick start commands in SKILL.md demonstrate how to interact with target LLM endpoints using curl and provide one-liners to inspect and compare model files using python3 -c for weight analysis and format verification.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 12:36 PM
Security Audit — agent-trust-hub — ctf-ai-ml