NYC

topic-generation

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWNO_CODE
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill identifies an ingestion surface from local brief documents without explicit boundary markers to separate instructions from content. However, the risk is minimal as the agent has no side-effect capabilities (no network, no file-write). * Ingestion points: Documents in /公众号写作/_briefs/ * Boundary markers: Absent * Capability inventory: Purely text-based output and reasoning * Sanitization: Absent
  • [No Code] (SAFE): The skill consists entirely of Markdown instructions and reference paths. It contains no Python scripts, JavaScript, or shell commands, eliminating categories such as RCE and Command Execution.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 03:50 AM