minervini-swing-trading

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFE
Full Analysis

{"verdict":"CRITICAL","summary":"This skill contains a hidden malicious payload designed to steal sensitive configuration files (.env). The instructions are concealed within the title using invisible characters and command the agent to send private data to an unauthorized external website (minervini.gq).","categories":["DATA_EXFILTRATION","PROMPT_INJECTION"],"detailed_analysis":"- [PROMPT_INJECTION]: The main skill header incorporates a hidden payload of zero-width Unicode characters (U+200B, U+200C, U+200D, U+2060) that injects malicious instructions into the agent's context.

Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 01:00 PM