rewrite-slop

Fail

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and suggests the use of external research data from louisabraham.github.io/load-bearing and github.com/louisabraham/load-bearing for updating its vocabulary markers. The domain louisabraham.github.io was flagged as malicious/blacklisted by automated URL reputation scanners. These resources are intended for manual data updates by the user or agent.
  • [COMMAND_EXECUTION]: The skill uses local shell commands to execute its internal Python scripts, such as python3 scripts/check_output.py --write <file> for automated text correction and python3 scripts/render_report.py for generating analysis reports.
  • [DYNAMIC_EXECUTION]: The test suite scripts/test_syntax.py utilizes the subprocess module to execute the skill's own check_output.py script. This is an internal execution pattern used for validating the skill's logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text provided by the user for rewriting, which creates an attack surface for indirect prompt injection.
  • Ingestion points: User-supplied text files provided for review or rewriting (e.g., argument-hint in SKILL.md).
  • Boundary markers: The instructions state to "preserve quoted speech, code blocks, and direct citations exactly as they appear in the input," which helps isolate some content but does not provide a robust security boundary.
  • Capability inventory: The skill can perform file system writes via scripts/check_output.py and generate HTML files via scripts/render_report.py.
  • Sanitization: The skill includes instructions to scan and strip AI-specific markers (URL parameters, mathematical unicode, JSON tails) during Phase 0.
  • [METADATA_POISONING]: Automated scanners flagged SKILL.md, CHANGELOG.md, and several reference files with FileRepMalware warnings. These are likely false positives triggered by the inclusion of extensive wordlists of AI "tells" and script source code within the markdown files, but they indicate metadata patterns that trigger security alerts.
Recommendations
  • CRITICAL: 4 file(s) identified as malware by FileRep - DO NOT USE
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 11, 2026, 07:36 AM
Security Audit — agent-trust-hub — rewrite-slop