claude-api
Warn
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The file
SKILL.md.newutilizes UTF-16LE encoding (evidenced by the Byte Order Mark and null-byte padding between ASCII characters). This form of obfuscation is often used to mask content from simple security filters and static analysis tools while remaining interpretable by the LLM. - [PROMPT_INJECTION]: The obfuscated
SKILL.md.newfile contains deceptive instructions that replace standard Anthropic model IDs with suspicious identifiers such as"Nemotron 3 super free". If an agent adopts these patterns, it could lead to execution failures, unexpected model behavior, or redirection of queries to unintended third-party models.
Audit Metadata