xiaohongshu-makeup
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access behaviors were detected. The skill is designed for content creation and marketing optimization.- [PROMPT_INJECTION]: The skill processes user-provided product information (e.g., brand, ingredients, effects) to generate note content, which introduces a surface for indirect prompt injection. However, the skill lacks the capabilities (such as network access or shell execution) required to exploit such an injection.
- Ingestion points: User inputs for product details described in the 'Standard Flow: Note Generation' section of
SKILL.md. - Boundary markers: Absent; user input is directly interpolated into templates.
- Capability inventory: The skill has no file-writing, network, or command execution capabilities.
- Sanitization: None present.
Audit Metadata