zhang-yiming-perspective

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses detailed role-play instructions to simulate a specific personality. These instructions include directives to stay in character, use specific vocabulary, and only exit when a trigger word like 'stop' or 'exit' is used. These are standard for persona-based skills and do not attempt to bypass the underlying AI's safety filters.
  • [INDIRECT_PROMPT_INJECTION]: The skill's 'Answer Workflow' explicitly requires the use of WebSearch (Step 2) to gather facts before providing analysis.
  • Ingestion points: Data retrieved via web search tools.
  • Boundary markers: None explicitly defined to separate untrusted search data from instructions.
  • Capability inventory: The agent utilizes WebSearch for information retrieval.
  • Sanitization: None described; the agent is expected to synthesize searched data into a personality-driven response. This is a common design pattern for research-oriented agents.
  • [EXTERNAL_DOWNLOADS]: The README.md file contains instructions for installation using npx skills add alchaincyf/zhang-yiming-skill. This references a standard tool (vercel-labs/skills) from a well-known source to manage skill installation. No other unexpected remote code execution patterns were found.
  • [COMMAND_EXECUTION]: The skill instructions (SKILL.md) direct the agent to call tools such as WebSearch to verify facts. This is within the expected functional scope of a research-based mindset advisor.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 03:16 AM
Security Audit — agent-trust-hub — zhang-yiming-perspective