documentary-brutalist-agency

Fail

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The REFERENCES.md file contains a link to https://drukstudio.framer.website/, which has been explicitly flagged as a phishing site by automated URL scanners.\n- [METADATA_POISONING]: Automated file scanners have flagged both SKILL.md and REFERENCES.md as malicious (FileRepMalware), indicating that the documentation or skill structure aligns with known malicious patterns or has a poor reputation.\n- [INDIRECT_PROMPT_INJECTION]: The skill instructions allow for the inclusion of untrusted user data (projects, quotes, links) into the generated agency website code without sanitization or clear boundary markers, creating a vulnerability to data-driven code injection.\n
  • Ingestion points: Instructions in SKILL.md to replace source names, projects, people, photography, quotes, and links with user-provided content.\n
  • Boundary markers: None; the skill does not instruct the agent to use delimiters or ignore potential commands within the external data.\n
  • Capability inventory: The skill generates active web content (HTML/JavaScript) based on design patterns and user input.\n
  • Sanitization: None identified; there are no directives to validate or escape user input before it is rendered in the final output.
Recommendations
  • CRITICAL: 2 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 21, 2026, 01:30 AM
Security Audit — agent-trust-hub — documentary-brutalist-agency