skills/bmz404/bmzskill/bmz-style/Gen Agent Trust Hub

bmz-style

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses directive language ('Must load', 'Must obey') to ensure consistent application of its internal framework, but no instructions aimed at bypassing safety guardrails or overriding system prompts were found.- [DATA_EXFILTRATION]: No sensitive file access, hardcoded credentials, or unauthorized network operations were identified. The external URLs referenced are all plain-text links to well-known music and social media platforms (NetEase Cloud Music and Douyin) for case study purposes.- [OBFUSCATION]: Analysis of the markdown content and metadata revealed no base64, hex-encoded strings, homoglyphs, or hidden characters intended to conceal malicious payloads.- [REMOTE_CODE_EXECUTION]: The skill does not include any scripts, package installation commands (npm, pip), or patterns involving dynamic code execution (eval, exec).- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied lyrics and descriptions. While this is a potential ingestion point for untrusted data, the skill's output is limited to text recommendations and prompts, posing no risk of privilege escalation or tool abuse.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 02:26 AM
Security Audit — agent-trust-hub — bmz-style