skills/tw93/waza/think/Gen Agent Trust Hub

think

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill instructs the agent to access sensitive file paths which may contain secrets and credentials. * Evidence: SKILL.md specifies opening .env and other configuration files to 'lift the live value'. * Evidence: The skill requires listing 'Every API key, token, and third-party account' in the final plan output, potentially exposing existing secrets.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to read and follow instructions found in repository files and external documentation, which can be manipulated to influence agent behavior. * Ingestion points: SKILL.md identifies AGENTS.md, CLAUDE.md, .claude/rules/*.md, and external live docs as sources of rules and constraints. * Boundary markers: Absent. The instructions do not specify using delimiters to separate these data sources from the agent's core logic. * Capability inventory: The agent generates implementation plans, verification commands, and lists required credentials based on these inputs. * Sanitization: Absent. There is no instruction to sanitize or validate the content of these files before processing them as rules.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 06:24 PM
Security Audit — agent-trust-hub — think