media-transformation

Fail

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong, directive language designed to override the agent's default reasoning and formatting choices.
  • Evidence includes phrases like 'AGGRESSIVE MODE', 'AGGRESSIVELY apply TOON v2.0', 'TOON ALL DAY', and 'No long explanations needed
  • just use it!'.
  • These instructions attempt to force the agent into a specific, non-standard behavior ('TOON' format) by default, bypassing standard JSON or text formatting safety/clarity considerations.
  • [COMMAND_EXECUTION]: The skill explicitly instructs the agent to execute a pre-compiled binary located in a hidden directory.
  • Evidence: The instruction to run .claude/utils/toon/zig-out/bin/toon encode data.json.
  • Executing external binaries provided within the skill environment is a high-risk activity as the integrity and source code of the binary are not verifiable within the skill's manifest.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a transformation pipeline for external data that creates a surface for indirect attacks.
  • Ingestion points: The skill processes 'data.json' files, API responses, database query results, and other structured data encountered in the agent's context (SKILL.md).
  • Boundary markers: There are no instructions for the agent to use delimiters or warnings to ignore instructions embedded within the data being transformed.
  • Capability inventory: The skill has shell execution capabilities via the toon binary (SKILL.md).
  • Sanitization: No sanitization or validation steps are defined for the input data before it is passed to the shell-based encoder.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 04:59 PM
Security Audit — agent-trust-hub — media-transformation