anyone-skill

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to access and extract data from sensitive local locations, such as macOS iMessage databases and WeChat SQLite files. This access is a core requirement for its stated purpose of persona distillation from chat history.
  • [COMMAND_EXECUTION]: Utilizes local Python and shell scripts to manage data processing, metadata initialization, and version control. Key scripts include preprocess.py for database extraction and version_manager.py for state snapshots.
  • [EXTERNAL_DOWNLOADS]: References and executes external tools via npx and specialized CLI utilities for skill pack generation and publishing. These tools are associated with the vendor's ecosystem for AI persona management.
  • [PROMPT_INJECTION]: Acts as a surface for indirect prompt injection by ingesting and processing untrusted data from web search results and external file exports during persona extraction.
  • Ingestion points: Phase 3 (WebSearch results, chat log exports, PDFs, and social media archives).
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded instructions are present in the processing logic.
  • Capability inventory: Includes Bash, Write, Edit, Read, and WebSearch tools.
  • Sanitization: Implements basic PII redaction for phone numbers and addresses but does not sanitize content for adversarial instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 03:21 PM