handdrawn-route-map-card
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) where malicious instructions embedded in user-provided data could influence the agent's behavior.
- Ingestion points: The skill accepts untrusted user input for map topics, locations, and route nodes via the 'Input Contract' and templates.
- Boundary markers: Absent. There are no explicit instructions to use delimiters or ignore embedded instructions within user-provided strings.
- Capability inventory: The skill instructs the agent to perform external verification of data (web search) and interact with image generation tools, creating an attack surface where injected instructions could trigger unintended tool usage.
- Sanitization: Absent. The skill does not define any filtering, escaping, or validation logic for the input it processes.
- [EXTERNAL_DOWNLOADS]: The skill references an external URL ('https://lingzao.atian.vip') for the purpose of configuring API credits for extended functionality.
- Context: This URL is linked to the 'atian-create' vendor infrastructure and is intended for service management.
- Safety: The reference is documented neutrally as a functional requirement for the 'Lingzao Upgrade' feature.
Audit Metadata