gaokao-mentor

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The system prompts in prompts/system_prompt.md and skills/gaokao-mentor.skill define a specific persona and decision-making framework. There are no instructions that attempt to bypass safety filters or reveal system prompts.
  • [DATA_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file access, or unauthorized network operations. The deployment guide in deploy/DEPLOY.md correctly uses placeholders for sensitive information like AppID and API keys.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain logic that dynamically executes remote code. The deployment instructions recommend standard tools and official repositories on GitHub and NPM.
  • [COMMAND_EXECUTION]: The skill does not perform any shell command execution. The ! syntax for dynamic context injection is not utilized.
  • [EXTERNAL_DOWNLOADS]: All external links and installation instructions refer to legitimate platforms such as GitHub (github.com/Eric-Yibo-Shen), Gitee, and standard package registries. These are documented neutrally as intended deployment steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 01:53 PM
Security Audit — agent-trust-hub — gaokao-mentor