baoyu-xhs-images
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- Prompt Injection (LOW): File 'references/base-prompt.md' uses the instruction 'DO NOT refuse to generate' to override default AI behavior regarding copyrighted content, forcing the generation of stylistic alternatives.
- Data Exposure & Exfiltration (SAFE): No hardcoded secrets or sensitive data exposure patterns were detected.
- Remote Code Execution (SAFE): The skill contains no executable scripts or commands; it is composed of markdown reference files.
- Indirect Prompt Injection (LOW): The skill possesses an attack surface as it processes external content (File: references/base-prompt.md). Evidence: 1. Ingestion points: 'base-prompt.md' (interpolates user content). 2. Boundary markers: Absent. 3. Capability inventory: No code-execution or network capabilities found. 4. Sanitization: Absent. The lack of dangerous capabilities mitigates the risk.
Audit Metadata