huashu-article-edit

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text provided by users in the form of articles, which creates a surface for indirect prompt injection where malicious instructions could be hidden in the article content.
  • Ingestion points: The process begins by using a 'Read' tool to ingest the full text of a target article into the agent's context (Step 1).
  • Boundary markers: The instructions do not specify the use of XML tags or other delimiters to isolate the article content from the agent's instructions.
  • Capability inventory: The skill possesses file read and write capabilities to allow for editing and saving changes.
  • Sanitization: While no technical sanitization is mentioned, the skill includes a critical security control by requiring the agent to wait for explicit user confirmation of the modification list before performing any edits (Step 2).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:55 AM
Security Audit — agent-trust-hub — huashu-article-edit