baoyu-xhs-images

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a transparent and highly structured workflow for processing text into visual infographic series, using localized files for configuration and session management.
  • [SAFE]: File system operations are confined to standard behaviors: reading user preferences from a dedicated configuration file (EXTEND.md) and creating a clearly defined directory structure (xhs-images/{topic-slug}/) for session data, analysis, and generated assets.
  • [SAFE]: Shell commands found in the instructions (e.g., test -f or Test-Path) are used exclusively for environment discovery to locate the preference file across project, user, or XDG configuration directories.
  • [SAFE]: The skill identifies an attack surface for indirect prompt injection by ingesting and processing untrusted user articles; however, the impact is minimized by the skill's lack of high-risk capabilities like external network communication or arbitrary script execution.
  • [SAFE]: All external resource references, such as the homepage URL, point to legitimate project repositories and well-known services without signs of typosquatting or malicious intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 10:59 AM