baoyu-comic
Pass
Audited by Gen Agent Trust Hub on Mar 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows a legitimate and well-structured workflow for generating knowledge comics from user-provided content without any detected malicious intent.\n- [COMMAND_EXECUTION]: The skill uses the
bunruntime to execute a local script (scripts/merge-to-pdf.ts) for PDF generation and suggests system-level tools likepngquant,optipng, orsipsfor image optimization.\n- [EXTERNAL_DOWNLOADS]: The skill requires thebunandnpxruntimes as specified in its metadata and utilizes thepdf-libpackage within its PDF merging script.\n- [PROMPT_INJECTION]: The skill processes external text material, which creates a surface for indirect prompt injection. Ingestion points: user-supplied source files (source.md). Boundary markers: structured storyboard and prompt templates. Capability inventory: local file read/write operations, script execution viabun, and delegation to external image generation skills. Sanitization: implicit filtering occurs through the AI-led analysis and simplification phases. No direct or malicious injection attempts were detected.\n- [DATA_EXFILTRATION]: No evidence of credential exposure, unauthorized network activity, or access to sensitive system directories was found. The skill operates within localized project directories.
Audit Metadata