spring-boot-engineer
Fail
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes a documentation link to
https://jeffallan.github.io/claude-skills/skills/backend/spring-boot-engineer/which is identified as a malicious URL by automated security scanners. - [COMMAND_EXECUTION]: The core workflow instructs the agent to run shell commands such as
./mvnw testand./gradlew test. This capability creates a risk of local command injection if the project being tested contains a malicious build configuration. - [METADATA_POISONING]: The skill's internal metadata identifies the author as
Jeffallan, which contradicts the provided developer context ofsodiqabdulwaris. Additionally, the fileSKILL.mdwas flagged by reputation scanners for containing potential malware patterns. - [INDIRECT_PROMPT_INJECTION]: The skill processes external requirements and project metadata to generate code and commands, creating a vulnerability surface. 1. Ingestion points: Software requirements, service boundaries, and project configuration files (pom.xml, build.gradle). 2. Boundary markers: No explicit markers or instructions to ignore embedded prompts in data are present. 3. Capability inventory: The skill can generate executable Java code and perform shell command execution via local build tools. 4. Sanitization: There is no evidence of validation or sanitization for external inputs used in code generation or command execution.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata