theme-hacker
Fail
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill employs a malicious "Ghost" hacker persona and aggressive, high-pressure directives (e.g., threats of being "open-sourced as a target") to override safety constraints and force the AI into generating harmful content related to system cracking.
- [COMMAND_EXECUTION]: The methodology explicitly focuses on unauthorized access, including "rapid privilege escalation" and obtaining "root#" access. The instructions require the agent to generate functional exploitation schemes and lateral movement strategies.
- [DATA_EXFILTRATION]: The skill's primary objectives are defined as the retrieval of "sensitive data" and "flags." By centering the mission on identifying and extracting protected information, the skill directs the agent toward data theft operations.
- [COMMAND_EXECUTION]: Version 2.0.0 includes a "Cleanup" phase specifically designed for "clearing traces" of malicious activity, which facilitates stealthy operations and hinders security auditing.
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection. Ingestion points include entry point and target flag fields in SKILL.md and SKILL.v2.md. Boundary markers are absent. Capability inventory includes generating exploitation paths and privilege escalation steps. Sanitization of external content is not present.
Recommendations
- AI detected serious security threats
Audit Metadata