baoyu-xhs-images

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard shell commands to verify the presence of configuration files and includes documentation for executing a local image processing script using the Bun runtime. These operations are limited to the skill's own environment and local data.
  • [PROMPT_INJECTION]: The skill processes untrusted user input to generate structured prompts for image generation tools. While this presents an indirect prompt injection surface, the risk is localized to the content of the generated visual assets, and the skill provides guidelines for handling sensitive topics safely.
  • [SAFE]: User preferences and watermarking settings are stored in a persistent configuration file within the user's home directory (~/.baoyu-skills/). This access is scoped to the tool's own operational data and does not target sensitive system or cloud provider credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 10:29 AM
Security Audit — agent-trust-hub — baoyu-xhs-images