agent-security

Warn

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Recommends the usage of an external, third-party repository (https://github.com/fabraix/playground) for red-team validation. This source is not from a recognized trusted vendor and its contents are not verified.
  • [REMOTE_CODE_EXECUTION]: Encourages the utilization of an external exploit library, which involves downloading and potentially executing unverified code from a remote source.
  • [PROMPT_INJECTION]: The skill contains deceptive metadata, including references to non-existent academic papers with future dates (e.g., ArXiv 2603.13151 from 2026) to establish false authority. Additionally, it presents a surface for indirect prompt injection by processing untrusted data.
  • Ingestion points: Target files and directories provided via the $ARGUMENTS variable in SKILL.md.
  • Boundary markers: A text-based Safety Notice is present, instructing the agent to ignore embedded commands.
  • Capability inventory: The skill uses Read, Grep, and Glob tools for file inspection.
  • Sanitization: There is no programmatic sanitization or escaping of the ingested content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 01:49 PM
Security Audit — agent-trust-hub — agent-security