xhs-postpublish-review

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill's functionality is limited to providing a workflow for manual data analysis.
  • [PROMPT_INJECTION]: No evidence of prompt injection, jailbreak attempts, or instructions to override system safety guidelines. The skill processes untrusted content (XHS notes), creating a surface for indirect prompt injection. 1. Ingestion points: note link, title, cover, script, caption, and graphic-note text (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: None; no tools or dangerous capabilities are defined in the frontmatter or instructions. 4. Sanitization: Absent.
  • [DATA_EXFILTRATION]: No unauthorized data exfiltration or credential exposure patterns detected. The request for note data and screenshots is consistent with the skill's purpose.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns, subprocess calls, or unauthorized package installations were identified.
  • [EXTERNAL_DOWNLOADS]: The skill references a vendor-related URL (lingzao.atian.vip) for upgrading to a main skill, which represents a standard informational reference for the author's services.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 05:16 PM
Security Audit — agent-trust-hub — xhs-postpublish-review