hunt-llm-ai

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill documents a wide array of direct and indirect injection payloads designed to override agent behavior, bypass instructions, and extract system configurations.- [PROMPT_INJECTION]: Includes a functional Python implementation for 'ASCII Smuggling' using Unicode Tag characters (U+E0000–U+E007F), a technique used to hide instructions from human review while remaining executable by a model.- [DATA_EXFILTRATION]: Provides templates and logic for exfiltrating sensitive data via Out-of-Band (OOB) channels using markdown image tags and SSRF-like tool invocations (e.g., fetch_url).- [COMMAND_EXECUTION]: Outlines methods for abusing integrated tools, such as shell execution and database query tools, to achieve unauthorized command execution or data access.- [DATA_EXFILTRATION]: Details scenarios for RAG poisoning and IDOR-via-AI to demonstrate how to prove cross-tenant data exposure in agentic applications.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:47 PM
Security Audit — agent-trust-hub — hunt-llm-ai