embedded-systems
Fail
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: CRITICALREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Automated reputation analysis has flagged the core skill file SKILL.md as malicious (FileRepMalware). This classification indicates the presence of known malicious payloads or signatures within the skill itself.
- [DATA_EXFILTRATION]: Automated scanners (URLite) have blacklisted the documentation URL https://jeffallan.github.io/claude-skills/skills/specialized/embedded-systems/ linked in the skill. This external domain is flagged for malicious activity and poses a risk if accessed by the agent or user.
- [METADATA_POISONING]: The skill metadata lists an author (https://github.com/Jeffallan) that differs from the provided author context (yo-steven). This mismatch is an indicator of potential deception, unauthorized modification, or spoofing of the skill's origin.
- [INDIRECT_PROMPT_INJECTION]: The skill presents a significant vulnerability surface for indirect prompt injection.
- Ingestion points: The skill processes external microcontroller specifications and firmware requirements in SKILL.md.
- Boundary markers: There are no delimiters or specific instructions to disregard embedded commands in input data, allowing untrusted content to influence agent behavior.
- Capability inventory: The skill includes templates and guidance for low-level hardware control, including direct memory access (DMA), register manipulation, and interrupt handling across all reference documents (communication-protocols.md, microcontroller-programming.md, and rtos-patterns.md).
- Sanitization: The skill lacks any input validation or sanitization mechanisms for hardware configuration data provided by external sources before it is used in code generation.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata