baoyu-xhs-images

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Prompt Injection (LOW): File 'references/base-prompt.md' uses the instruction 'DO NOT refuse to generate' to override default AI behavior regarding copyrighted content, forcing the generation of stylistic alternatives.
  • Data Exposure & Exfiltration (SAFE): No hardcoded secrets or sensitive data exposure patterns were detected.
  • Remote Code Execution (SAFE): The skill contains no executable scripts or commands; it is composed of markdown reference files.
  • Indirect Prompt Injection (LOW): The skill possesses an attack surface as it processes external content (File: references/base-prompt.md). Evidence: 1. Ingestion points: 'base-prompt.md' (interpolates user content). 2. Boundary markers: Absent. 3. Capability inventory: No code-execution or network capabilities found. 4. Sanitization: Absent. The lack of dangerous capabilities mitigates the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:48 PM