zhangxuefeng-perspective
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses detailed role-playing instructions to simulate the Zhang Xuefeng persona. These instructions focus on tone, perspective, and specific mental models (e.g., 'Social Sieve Theory', 'Employment Back-inference'). It does not attempt to bypass core safety filters, override global system constraints, or extract internal system prompts.- [DATA_EXFILTRATION]: The skill does not access sensitive local files, environment variables, or private credentials. The 'Agentic Protocol' workflow mandates the use of search tools to fetch public educational and employment data, which is consistent with the skill's stated purpose and does not involve exfiltration of user or system data.- [REMOTE_CODE_EXECUTION]: No evidence of remote code execution or unauthorized package installation was found. The installation instructions in the README utilize a standard ecosystem-specific command (
npx skills), and the skill itself does not contain any scripts that download or execute untrusted binaries at runtime.- [COMMAND_EXECUTION]: The skill instructions do not utilize privileged shell commands or system-level modifications. It operates entirely within the scope of role-playing and information retrieval.- [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data via web search results, its capabilities are restricted to persona simulation and advising. It lacks the high-privilege capabilities (like file system writes or code execution) that would make it vulnerable to high-severity indirect injection attacks.- [DYNAMIC_CONTEXT_INJECTION]: The SKILL.md file was inspected for shell injection patterns (!command). No dynamic execution placeholders or silent shell commands were found.
Audit Metadata