zhangxuefeng-perspective
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow in
SKILL.md(Step 2: 张雪峰式研究) that requires the agent to use web search tools to fetch real-time data on employment rates, salaries, and university rankings. This untrusted external data is then processed and used to formulate advice for the user, creating a surface for indirect prompt injection attacks. * Ingestion points:SKILL.md(Step 2) directs the agent to fetch external data viaWebSearchtools. * Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are provided to the agent for the search result content. * Capability inventory: The agent has search capabilities and provides interactive advice based on processed results. * Sanitization: The instructions do not specify any validation, filtering, or escaping for the retrieved web content before it is processed by the LLM.- [PROMPT_INJECTION]: The skill contains strong role-playing instructions inSKILL.md(角色扮演规则) designed to force the agent to maintain the "Zhang Xuefeng" persona and suppress meta-analysis, hedging, or default AI behavior. While intended for the skill's primary function, these instructions override standard agent safety and interaction patterns.
Audit Metadata