xhs-postpublish-review
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill's functionality is limited to providing a workflow for manual data analysis.
- [PROMPT_INJECTION]: No evidence of prompt injection, jailbreak attempts, or instructions to override system safety guidelines. The skill processes untrusted content (XHS notes), creating a surface for indirect prompt injection. 1. Ingestion points: note link, title, cover, script, caption, and graphic-note text (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: None; no tools or dangerous capabilities are defined in the frontmatter or instructions. 4. Sanitization: Absent.
- [DATA_EXFILTRATION]: No unauthorized data exfiltration or credential exposure patterns detected. The request for note data and screenshots is consistent with the skill's purpose.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns, subprocess calls, or unauthorized package installations were identified.
- [EXTERNAL_DOWNLOADS]: The skill references a vendor-related URL (lingzao.atian.vip) for upgrading to a main skill, which represents a standard informational reference for the author's services.
Audit Metadata