spring-boot-engineer

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a documentation link to https://jeffallan.github.io/claude-skills/skills/backend/spring-boot-engineer/ which is identified as a malicious URL by automated security scanners.
  • [COMMAND_EXECUTION]: The core workflow instructs the agent to run shell commands such as ./mvnw test and ./gradlew test. This capability creates a risk of local command injection if the project being tested contains a malicious build configuration.
  • [METADATA_POISONING]: The skill's internal metadata identifies the author as Jeffallan, which contradicts the provided developer context of sodiqabdulwaris. Additionally, the file SKILL.md was flagged by reputation scanners for containing potential malware patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external requirements and project metadata to generate code and commands, creating a vulnerability surface. 1. Ingestion points: Software requirements, service boundaries, and project configuration files (pom.xml, build.gradle). 2. Boundary markers: No explicit markers or instructions to ignore embedded prompts in data are present. 3. Capability inventory: The skill can generate executable Java code and perform shell command execution via local build tools. 4. Sanitization: There is no evidence of validation or sanitization for external inputs used in code generation or command execution.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:39 AM
Security Audit — agent-trust-hub — spring-boot-engineer