drive-motivation

Warn

Audited by Gen Agent Trust Hub on Apr 4, 2026

Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The operational sections of SKILL.md (Prerequisites, Instructions, Output, and Error Handling) are copied from an unrelated technical domain involving 'ORM' (Object-Relational Mapping) database configuration. These directives instruct the agent to assess ORM settings and handle authentication failures for database resources, which could lead the agent to attempt unauthorized or unintended operations on a user's database environment while under the guise of the 'Drive Motivation' framework.
  • [DATA_EXFILTRATION]: The 'Further Reading' section of SKILL.md contains Amazon product links with embedded affiliate tracking tags (tag=wondelai00-20). This allows for unauthorized monetization and allows the affiliate account owner to track interactions with the recommended resources.
  • [NO_CODE]: This skill consists exclusively of documentation and instructions in Markdown format and does not include any executable code or external software dependencies.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 4, 2026, 12:36 PM