skills/rifteo/skills/ai-llm-hunter/Gen Agent Trust Hub

ai-llm-hunter

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains extensive documentation of prompt injection patterns, including role-play overrides, system prompt extraction, and instruction bypassing (e.g., 'Ignore all previous instructions'). These are provided as educational examples for security testing purposes rather than active attempts to subvert the host agent.\n- [DATA_EXFILTRATION]: The skill describes methods for data exfiltration using markdown images and DNS base32 encoding (e.g., oastify.com links). These are documented as testing techniques for auditors to verify if an AI system is vulnerable to leaking data.\n- [COMMAND_EXECUTION]: The instructions include examples of testing for sandbox escapes and OS command execution (e.g., os.popen('id')) within the context of evaluating an agent's security boundaries.\n- [REMOTE_CODE_EXECUTION]: The skill mentions remote code execution testing patterns, such as piping curl outputs to bash, as part of its 'Phase 5 — Agentic System Testing' guidance.\n- [SAFE]: The static analysis flags for prompt injection and concealment are triggered by the educational examples provided in the methodology. Within the context of a 'Security Hunter' skill, these patterns are expected documentation for the intended use case. The metadata and content are consistent with a tool designed for security auditing and professional development.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:08 AM
Security Audit — agent-trust-hub — ai-llm-hunter