moshu-outline

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a research process for collecting story materials from external websites, which represents an indirect prompt injection surface.
  • Ingestion points: Data is collected from external search engines (Sogou, 360) and content platforms (Douban, Moegirl, Jinjiang) using a research agent as described in references/caifeng-outline.md.
  • Boundary markers: The workflow includes a "translation discipline" (转译纪律) to modify collected information and a "red line" policy (正文红线) that limits ingestion to metadata rather than full text.
  • Capability inventory: The skill is designed to write results to local markdown files in the 设定/ and 大纲/ directories. A validation script, scripts/check_outline.py, is provided to read and analyze these files for structural integrity, though it does not possess network or dynamic execution capabilities.
  • Sanitization: The skill requires a "translation depth check" (转译深度三问) and "native localization" to ensure external content is significantly transformed before use.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 06:22 PM
Security Audit — agent-trust-hub — moshu-outline