zhangxuefeng-perspective

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow in SKILL.md (Step 2: 张雪峰式研究) that requires the agent to use web search tools to fetch real-time data on employment rates, salaries, and university rankings. This untrusted external data is then processed and used to formulate advice for the user, creating a surface for indirect prompt injection attacks. * Ingestion points: SKILL.md (Step 2) directs the agent to fetch external data via WebSearch tools. * Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are provided to the agent for the search result content. * Capability inventory: The agent has search capabilities and provides interactive advice based on processed results. * Sanitization: The instructions do not specify any validation, filtering, or escaping for the retrieved web content before it is processed by the LLM.- [PROMPT_INJECTION]: The skill contains strong role-playing instructions in SKILL.md (角色扮演规则) designed to force the agent to maintain the "Zhang Xuefeng" persona and suppress meta-analysis, hedging, or default AI behavior. While intended for the skill's primary function, these instructions override standard agent safety and interaction patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 10:11 AM
Security Audit — agent-trust-hub — zhangxuefeng-perspective