ian-xiaohei-illustrations

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves ingesting and analyzing external data provided by the user to generate illustration strategies and prompts. This creates a surface where malicious instructions embedded in the source articles or linked content could attempt to influence the agent's behavior.
  • Ingestion points: The skill reads user-supplied articles, links, Notion pages, and Markdown files as specified in the 'Understand the article' step of SKILL.md.
  • Boundary markers: The instructions lack explicit requirements for using delimiters or 'ignore embedded instructions' warnings when processing the retrieved text.
  • Capability inventory: The agent has the capability to generate images (likely via an image generation tool) and write files to the local workspace (under assets/<article-slug>-illustrations/ as specified in step 5 of SKILL.md).
  • Sanitization: No sanitization or filtering logic is prescribed for the external content before it is processed for metaphor extraction.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 06:36 PM
Security Audit — agent-trust-hub — ian-xiaohei-illustrations