zhang-yiming-perspective

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions include specific directives to suppress the repetition of safety disclaimers (e.g., "不要每次在结尾加『政治变量我没法分析』这句话"). These directives are intended to override the model's standard behavior of providing frequent safety context in favor of maintaining a consistent persona.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an "Agentic Protocol" that mandates the use of web search tools to gather information on external entities like products, companies, and market trends (specified in SKILL.md under Step 2).
  • Ingestion points: The agent context is populated with untrusted data retrieved via WebSearch when analyzing specific cases or products.
  • Boundary markers: The instructions do not define clear delimiters or "ignore embedded instructions" warnings for the content retrieved from the web.
  • Capability inventory: The skill utilizes web search capabilities and sophisticated analytical reasoning to process retrieved data.
  • Sanitization: There are no specified sanitization or validation mechanisms to filter malicious instructions that might be embedded in searched web pages or third-party reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 10:11 AM
Security Audit — agent-trust-hub — zhang-yiming-perspective