xiaohongshu-makeup

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access behaviors were detected. The skill is designed for content creation and marketing optimization.- [PROMPT_INJECTION]: The skill processes user-provided product information (e.g., brand, ingredients, effects) to generate note content, which introduces a surface for indirect prompt injection. However, the skill lacks the capabilities (such as network access or shell execution) required to exploit such an injection.
  • Ingestion points: User inputs for product details described in the 'Standard Flow: Note Generation' section of SKILL.md.
  • Boundary markers: Absent; user input is directly interpolated into templates.
  • Capability inventory: The skill has no file-writing, network, or command execution capabilities.
  • Sanitization: None present.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 11:28 AM
Security Audit — agent-trust-hub — xiaohongshu-makeup