baoyu-comic

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-supplied content (text, files, or URLs) to generate comic storyboards and image prompts.
  • Ingestion points: Source content is ingested and saved to source-{slug}.md in Step 1.1 (references/workflow.md).
  • Boundary markers: The skill does not explicitly define delimiters to separate untrusted content from its internal instructions.
  • Capability inventory: The skill uses write_file to save content and curl via the terminal to download images from URLs returned by the image_generate tool (Step 7.2, references/workflow.md).
  • Sanitization: The skill includes a proactive security instruction to "Strip secrets — scan source content for API keys, tokens, or credentials before writing any output file" (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 07:35 PM
Security Audit — agent-trust-hub — baoyu-comic