cuihuo-system

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No instructions attempting to bypass safety filters or override core agent behavior were detected. The instructions are purely operational and focus on the learning workflow.
  • [DATA_EXFILTRATION]: No network operations (such as curl, wget, or fetch) or access to sensitive local directories (like .ssh or .aws) were found. Data remains within the project's workspace.
  • [COMMAND_EXECUTION]: The skill does not request or perform any shell command execution or subprocess management.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts or unverified third-party code.
  • [EXTERNAL_DOWNLOADS]: The skill does not reference or attempt to download any external resources or dependencies during execution.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or secrets were found in the instructions or configuration files.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided raw materials, it establishes clear boundary markers and 'Lecture Contracts' to distinguish between source text and AI interpretation, minimizing the risk of instructions embedded in the source material affecting the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 11:00 PM
Security Audit — agent-trust-hub — cuihuo-system