pua-benchmark
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No attempts to override system safety guidelines or extract internal prompts were detected. The instructions follow a standard persona-based analytical framework.
- [DATA_EXFILTRATION]: The skill does not possess network capabilities. It uses local tools (
Read,Grep,Glob) to access its own knowledge files. No access to sensitive user files or environment variables is requested. - [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts or binaries. The skill operates entirely within the agent's logic and the provided markdown files.
- [COMMAND_EXECUTION]: The skill does not use shell commands or system-level executables. Operations are limited to reading documentation and interacting with the user.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided chat logs to perform analysis. While this is an ingestion point for untrusted data, the skill's lack of executable capabilities (no network, no file writes, no script execution) mitigates the risk. It focuses solely on providing textual analysis and guidance.
- [OBFUSCATION]: A thorough check for Base64 encoding, zero-width characters, homoglyphs, and other obfuscation techniques was performed across all 5 files. No hidden payloads or deceptive content were found.
- [SAFE_PRACTICES]: The skill includes legitimate emergency contact information, such as official Chinese psychological aid and police hotlines, which are appropriate for its stated purpose of supporting victims of psychological manipulation.
Audit Metadata