st3gg

Fail

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill constructs shell commands by interpolating user-provided inputs such as <text_to_hide>, <input_image>, and <output_image> directly into the command line executed via Python. While values are enclosed in double quotes, this pattern is susceptible to command injection via shell metacharacters.
  • [PROMPT_INJECTION]: The skill features a specific inject action used to list, display, and generate prompt injection templates. This provides an integrated capability for generating instructions meant to bypass AI safety guardrails.
  • [DATA_EXFILTRATION]: The decode action extracts hidden data from images and instructs the agent to display the result. This represents an indirect prompt injection surface where a malicious image could contain instructions that are executed by the agent upon processing the decoded content.
  • [DATA_EXFILTRATION]: The inject show <template_name> and inject templates commands suggest the tool contains a library of injection payloads, which may include instructions for data exfiltration or system prompt extraction.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 17, 2026, 01:13 PM