outline-figure-explainer

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strict instructional language ('style locked', 'word-for-word') to ensure consistency in generated image prompts. These are standard prompt engineering constraints and do not attempt to bypass AI safety filters or override system-level instructions.
  • [DATA_EXPOSURE]: No hardcoded credentials, sensitive file paths (e.g., .ssh, .env), or environment variables were detected in the skill instructions or example files.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any network operations (curl, wget) or download external scripts. References to external specifications like 'gpt-image-prompt-spec' are documented as conceptual templates rather than active resource fetches.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a framework for processing user-supplied concepts into image prompts. While it ingests external text, it lacks any high-privilege capabilities (such as code execution, file writing, or network access) that could be exploited via malicious input. The inclusion of 'Constraints' to prevent the generation of unauthorized text or logos serves as a functional safeguard for the output.
  • [OBFUSCATION]: Analysis for Base64 encoding, zero-width characters, homoglyphs, and hidden text patterns yielded no findings. The content consists of clear, human-readable Chinese and English instructions.
  • [DYNAMIC_EXECUTION]: The skill is entirely declarative and does not utilize any dynamic code execution methods such as eval(), runtime compilation, or shell command interpolation via the '!' syntax.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 04:12 AM
Security Audit — agent-trust-hub — outline-figure-explainer