ljg-writes
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDYNAMIC_CONTEXT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_CONTEXT_INJECTION]: The skill utilizes the shell execution syntax
!commandto run thedatecommand. This is used to generate timestamps for the output filename (~/Documents/notes/{时间戳}==z--...) and internal document metadata. This use case is localized and non-malicious. - [INDIRECT_PROMPT_INJECTION]: As a text rewriting and optimization tool, the skill naturally ingests untrusted user content. This presents a surface for indirect prompt injection; however, the skill's instructions strictly enforce a logical 'Writing Contract' and structured workflows, which helps focus the agent on structural analysis rather than arbitrary instruction following from the data.
Audit Metadata