the-fool

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes documentation links targeting 'jeffallan.github.io', which has been explicitly flagged as malicious by automated URL reputation scanners. While these are presented as documentation, the confirmed reputation hit on the host domain poses a significant risk to users visiting the link.
  • [METADATA_POISONING]: The skill's metadata contains inconsistent author information. While the execution context identifies the author as 'sodiqabdulwaris', the internal YAML frontmatter identifies the author as 'Jeffallan' and provides links to a domain flagged for malicious content. This inconsistency is often used to mask the origin of a skill or leverage the reputation of different accounts.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a reasoning engine that ingests external, untrusted content (plans, architectures, proposals) provided by the user to perform critical analysis.
  • Ingestion points: User-provided thesis statements and position descriptions are extracted directly from the conversation context (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or use specialized formatting (e.g., XML tags or blockquotes) to separate untrusted user input from the agent's core reasoning instructions.
  • Capability inventory: The skill primarily generates markdown reports and does not currently invoke external tools or scripts, limiting the immediate impact of an injection.
  • Sanitization: There is no mention of filtering, escaping, or validating the input data before it is incorporated into the reasoning workflow.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:39 AM
Security Audit — agent-trust-hub — the-fool