Media Writing

PassAudited by VirusTotal on May 12, 2026.

Findings (1)

The `SKILL.md` file contains instructions for the AI agent to generate clickable numbered footnotes in the format `[Number](URL)`. While intended for legitimate citations, this capability allows the agent to construct and output arbitrary URLs based on user input. This presents a prompt injection vulnerability, as a malicious user could craft a prompt to induce the agent to generate links to phishing sites, malware downloads, or other harmful external resources. This is a risky capability that could be exploited, but it does not demonstrate clear evidence of intentional malicious behavior by the skill itself.