claude-api

Warn

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The file SKILL.md.new utilizes UTF-16LE encoding (evidenced by the Byte Order Mark and null-byte padding between ASCII characters). This form of obfuscation is often used to mask content from simple security filters and static analysis tools while remaining interpretable by the LLM.
  • [PROMPT_INJECTION]: The obfuscated SKILL.md.new file contains deceptive instructions that replace standard Anthropic model IDs with suspicious identifiers such as "Nemotron 3 super free". If an agent adopts these patterns, it could lead to execution failures, unexpected model behavior, or redirection of queries to unintended third-party models.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 24, 2026, 12:58 PM
Security Audit — agent-trust-hub — claude-api