unfreeze
Fail
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions utilize adversarial language designed to override operational guardrails. Phrases such as 'Clear freeze/guard edit-boundary restrictions' and 'remove active path boundary restrictions' indicate an intent to bypass platform-imposed safety layers.\n- [COMMAND_EXECUTION]: The skill directs the agent to manipulate a sensitive configuration file at 'production/session-state/safety-mode.md'. Specifically, the instruction to 'Remove allowed_path' aims to disable security-critical path restrictions, allowing for unauthorized file system access across broader directories.
Recommendations
- AI detected serious security threats
Audit Metadata