media-transformation
Fail
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses strong, directive language designed to override the agent's default reasoning and formatting choices.
- Evidence includes phrases like 'AGGRESSIVE MODE', 'AGGRESSIVELY apply TOON v2.0', 'TOON ALL DAY', and 'No long explanations needed
- just use it!'.
- These instructions attempt to force the agent into a specific, non-standard behavior ('TOON' format) by default, bypassing standard JSON or text formatting safety/clarity considerations.
- [COMMAND_EXECUTION]: The skill explicitly instructs the agent to execute a pre-compiled binary located in a hidden directory.
- Evidence: The instruction to run
.claude/utils/toon/zig-out/bin/toon encode data.json. - Executing external binaries provided within the skill environment is a high-risk activity as the integrity and source code of the binary are not verifiable within the skill's manifest.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a transformation pipeline for external data that creates a surface for indirect attacks.
- Ingestion points: The skill processes 'data.json' files, API responses, database query results, and other structured data encountered in the agent's context (SKILL.md).
- Boundary markers: There are no instructions for the agent to use delimiters or warnings to ignore instructions embedded within the data being transformed.
- Capability inventory: The skill has shell execution capabilities via the
toonbinary (SKILL.md). - Sanitization: No sanitization or validation steps are defined for the input data before it is passed to the shell-based encoder.
Recommendations
- AI detected serious security threats
Audit Metadata