anyone-skill
Pass
Audited by Gen Agent Trust Hub on Apr 14, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to access and extract data from sensitive local locations, such as macOS iMessage databases and WeChat SQLite files. This access is a core requirement for its stated purpose of persona distillation from chat history.
- [COMMAND_EXECUTION]: Utilizes local Python and shell scripts to manage data processing, metadata initialization, and version control. Key scripts include preprocess.py for database extraction and version_manager.py for state snapshots.
- [EXTERNAL_DOWNLOADS]: References and executes external tools via npx and specialized CLI utilities for skill pack generation and publishing. These tools are associated with the vendor's ecosystem for AI persona management.
- [PROMPT_INJECTION]: Acts as a surface for indirect prompt injection by ingesting and processing untrusted data from web search results and external file exports during persona extraction.
- Ingestion points: Phase 3 (WebSearch results, chat log exports, PDFs, and social media archives).
- Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions are present in the processing logic.
- Capability inventory: Includes Bash, Write, Edit, Read, and WebSearch tools.
- Sanitization: Implements basic PII redaction for phone numbers and addresses but does not sanitize content for adversarial instructions.
Audit Metadata