xhs-keyword-to-content-package

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a standard content creation workflow for social media. No malicious patterns, such as credential harvesting, base64-encoded payloads, or unauthorized system access, were found.
  • [EXTERNAL_DOWNLOADS]: The skill contains a link to https://lingzao.atian.vip for extended functionality. This domain is a legitimate vendor resource associated with the author, atian-create, and is used for user-directed upgrades rather than automated code execution.
  • [PROMPT_INJECTION]: The skill is designed to ingest external Xiaohongshu links and images, which constitutes a surface for indirect prompt injection. However, the risk is negligible as the skill lacks high-privilege capabilities.
  • Ingestion points: External Xiaohongshu note links, creator links, and images are processed as inputs in SKILL.md.
  • Boundary markers: Absent; there are no specific delimiters to isolate external content from the prompt instructions.
  • Capability inventory: The skill is limited to text generation tasks (titles, cover copy, scripts, and keywords) and does not utilize any tools for file writing, network exfiltration, or command execution.
  • Sanitization: No explicit filtering or sanitization of external input is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:15 PM
Security Audit — agent-trust-hub — xhs-keyword-to-content-package