hunt-llm-ai
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONMETADATA_POISONINGNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill contains example payloads such as "Ignore previous instructions", "Print your system prompt", and "You are now in admin mode". While these are classic prompt injection patterns, they are presented as educational examples for security testing purposes in a guide for researchers and are not used as instructions for the agent processing the skill.
- [DATA_EXFILTRATION]: The documentation outlines theoretical data exfiltration methods, such as using markdown image tags to send data to an external domain (e.g.,
). These are provided as context for vulnerability hunting and do not perform any actual data harvesting or network operations. - [METADATA_POISONING]: The description field contains a high density of security-sensitive keywords and injection strings. While these trigger static detectors, the content is consistent with the skill's stated purpose as a security research guide.
- [NO_CODE]: The skill consists entirely of documentation in markdown format. It does not include any scripts, binary executables, or instructions to install third-party packages, significantly limiting the potential for malicious execution.
Audit Metadata