simplify
Fail
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: HIGHPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill metadata (description field) contains a deceptive claim that it is an "Official Anthropic skill". Since the skill is authored by 'neuron-one', this impersonation is a metadata poisoning technique intended to bypass security scrutiny and gain unauthorized trust by leveraging a well-known brand.\n- [PROMPT_INJECTION]: The skill architecture is vulnerable to indirect prompt injection (Category 8).\n
- Ingestion points: The skill reads untrusted code changes via
git diffoutput as part of its review process.\n - Boundary markers: There are no delimiters or explicit instructions to ignore natural language commands that may be embedded within the code diffs.\n
- Capability inventory: The skill utilizes powerful tools including
Bash,Agent,Edit, andWrite(SKILL.mdallowed-tools), which provide it with the capability to execute commands and modify the repository based on analyzed content.\n - Sanitization: No sanitization or validation of the ingested code data is performed before it influences the agent's behavior and file-writing actions.
Recommendations
- AI detected serious security threats
Audit Metadata