interview-master

Fail

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection] (HIGH): The skill's analysis scripts ingest untrusted repository content. * Ingestion points: analyze-commits.sh, extract-tech-stack.sh, and calculate-impact.py read output from git log. * Boundary markers: None; untrusted data is processed directly. * Capability inventory: Shell and Python execution of system commands. * Sanitization: None; commit messages are not sanitized.
  • [Metadata Poisoning] (MEDIUM): VALIDATION.md contains self-referential safety claims and a deceptive checklist that misrepresents file contents (e.g., claiming 2,000+ words for a file that is significantly shorter). It also references a missing SKILL.md.
  • [Command Execution] (MEDIUM): The scripts execute git operations. This capability can be leveraged to read metadata from sensitive directories like /etc or .ssh if the agent is coerced into using those paths.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 08:58 AM