st3gg
Fail
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill constructs shell commands by interpolating user-provided inputs such as
<text_to_hide>,<input_image>, and<output_image>directly into the command line executed via Python. While values are enclosed in double quotes, this pattern is susceptible to command injection via shell metacharacters. - [PROMPT_INJECTION]: The skill features a specific
injectaction used to list, display, and generate prompt injection templates. This provides an integrated capability for generating instructions meant to bypass AI safety guardrails. - [DATA_EXFILTRATION]: The
decodeaction extracts hidden data from images and instructs the agent to display the result. This represents an indirect prompt injection surface where a malicious image could contain instructions that are executed by the agent upon processing the decoded content. - [DATA_EXFILTRATION]: The
inject show <template_name>andinject templatescommands suggest the tool contains a library of injection payloads, which may include instructions for data exfiltration or system prompt extraction.
Recommendations
- AI detected serious security threats
Audit Metadata