fullstack-guardian
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides an external documentation link (
https://jeffallan.github.io/claude-skills/skills/security/fullstack-guardian/) inSKILL.mdthat has been flagged as malicious by automated URL reputation scanners. Directing users to known malicious infrastructure is a severe security risk. - [METADATA_POISONING]: The
SKILL.mdfile has been identified as a malicious file (FileRepMalware) by reputation scanners. This indicates that the skill's distribution or metadata is associated with malicious behavior. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted user requirements and convert them into architecture and source code without adequate safeguards.
- Ingestion points: User-provided feature scope and requirements in the "Gather requirements" phase (SKILL.md).
- Boundary markers: Absent; there are no instructions for the agent to use delimiters or to disregard instructions embedded within user requirements.
- Capability inventory: The skill generates highly sensitive infrastructure code, including
Dockerfile(references/backend-patterns.md), GitHub Actions CI/CD pipelines (references/integration-patterns.md), and database migration scripts (references/integration-patterns.md). - Sanitization: Absent; the instructions do not require validation or escaping of requirement strings before they are incorporated into code generation tasks.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata